Vulnerability index

Browse CVEs

539 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Qts HIGH 7.7
CVE-2018-0721

Buffer Overflow vulnerability in NAS devices. QTS allows attackers to run arbitrary code. This issue affects: QNAP Systems Inc. QTS version 4.2.6 and…

Mitigation only
Fix from $1,950 2018-11-27
Qts MEDIUM 5.5
CVE-2018-0719

Cross-site Scripting (XSS) vulnerability in NAS devices of QNAP Systems Inc. QTS allows attackers to inject javascript. This issue affects: QNAP Syst…

Mitigation only
Fix from $1,600 2018-11-27
Music Station CRITICAL 9.8
CVE-2018-0718

Command injection vulnerability in Music Station 5.1.2 and earlier versions in QNAP QTS 4.3.3 and 4.3.4 could allow remote attackers to run arbitrary…

Fix: after 5.1.2
Fix from $2,300 2018-09-14
Photo Station MEDIUM 6.1
CVE-2018-0715

Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the com…

Fix: after 5.7.0
Fix from $1,600 2018-08-27
Helpdesk CRITICAL 9.8
CVE-2018-0714

Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 2…

Fix: after 1.1.21
Fix from $2,300 2018-08-13
Q\'center HIGH 8.8
CVE-2018-0708EPSS 26%

Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run …

Fix: after 1.7.1063
Fix from $1,950 2018-07-17
Q\'center HIGH 8.8
CVE-2018-0709EPSS 14%

Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitr…

Fix: after 1.7.1063
Fix from $1,950 2018-07-17
Q\'center HIGH 8.8
CVE-2018-0710EPSS 14%

Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitra…

Fix: after 1.7.1063
Fix from $1,950 2018-07-17
Q\'center HIGH 7.2
CVE-2018-0707EPSS 59%

Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to…

Fix: after 1.7.1063
Fix from $1,950 2018-07-17
Q\'center HIGH 8.8
CVE-2018-0706EPSS 49%

Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to access sensitive i…

Fix: after 1.7.1063
Fix from $1,950 2018-07-17
Qts CRITICAL 9.8
CVE-2018-0712

Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 and their earlier…

Fix: after 4.3.4
Fix from $2,300 2018-06-21
Qts MEDIUM 6.1
CVE-2017-13072

Cross-site scripting (XSS) vulnerability in App Center in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20171213, QTS 4.3.4 build 20171223, and thei…

Mitigation only
Fix from $1,600 2018-06-21
Nas Proxy Server CRITICAL 9.8
CVE-2017-7637

QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to run arbitrary OS commands against the system with root privileges.

Fix: 1.3.0+
Fix from $2,300 2018-06-05
Nas Proxy Server HIGH 8.8
CVE-2017-7635

QNAP NAS application Proxy Server through version 1.2.0 does not utilize CSRF protections.

Fix: 1.3.0+
Fix from $1,950 2018-06-05
Nas Proxy Server MEDIUM 6.1
CVE-2017-7636

Cross-site scripting (XSS) vulnerability in QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to inject arbitrary web s…

Fix: 1.3.0+
Fix from $1,600 2018-06-05
Nas Proxy Server MEDIUM 5.3
CVE-2017-7639

QNAP NAS application Proxy Server through version 1.2.0 does not authenticate requests properly. Successful exploitation can lead to change of the se…

Fix: 1.3.0+
Fix from $1,600 2018-06-05
Qts MEDIUM 6.1
CVE-2018-0711

Cross-site scripting (XSS) vulnerability in QNAP QTS 4.3.3 build 20180126, QTS 4.3.4 build 20180315, and their earlier versions could allow remote at…

Mitigation only
Fix from $1,600 2018-04-30
Photo Station MEDIUM 6.1
CVE-2017-13073

Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote a…

Fix: after 5.4.3
Fix from $1,600 2018-04-23
Qts MEDIUM 6.1
CVE-2017-7631

Cross-site scripting (XSS) vulnerability in the share link function of File Station of QNAP 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlie…

Mitigation only
Fix from $1,600 2018-03-27
Qts MEDIUM 6.1
CVE-2017-7632

Cross-site scripting (XSS) vulnerability in File Station of QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attacke…

Mitigation only
Fix from $1,600 2018-03-27
Qts MEDIUM 5.3
CVE-2017-7630

QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensitive information (firmware ver…

Mitigation only
Fix from $1,600 2018-03-27
Media Streaming Add On CRITICAL 9.8
CVE-2017-7640

QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against th…

Fix: after 430.1.2.0
Fix from $2,300 2018-03-08
Media Streaming Add On HIGH 8.8
CVE-2017-7641

QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not utilize CSRF protections.

Fix: after 430.1.2.0
Fix from $1,950 2018-03-08
Media Streaming Add On MEDIUM 6.5
CVE-2017-7638

QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitatio…

Fix: after 430.1.2.0
Fix from $1,600 2018-03-08
Media Streaming Add On MEDIUM 6.1
CVE-2017-7634

Cross-site scripting (XSS) vulnerability in QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attac…

Fix: after 430.1.2.0
Fix from $1,600 2018-03-08
Qfinder Pro HIGH 7.5
CVE-2017-7633

QNAP Qfinder Pro 6.1.0.0317 and earlier may expose sensitive information contained in NAS devices. If exploited, this may allow attackers to further …

Fix: after 6.1.0.0317
Fix from $1,950 2018-03-05
Qts CRITICAL 9.8
CVE-2017-17027

A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 2017111…

Fix: after 4.3.3.0378
Fix from $2,300 2017-12-21
Qts CRITICAL 9.8
CVE-2017-17028

A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) …

Fix: after 4.3.3.0378
Fix from $2,300 2017-12-21
Qts CRITICAL 9.8
CVE-2017-17029

A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 2017…

Fix: after 4.3.3.0378
Fix from $2,300 2017-12-21
Qts CRITICAL 9.8
CVE-2017-17030

A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 2017…

Fix: after 4.3.3.0378
Fix from $2,300 2017-12-21