Vulnerability index

Browse CVEs

539 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Qts CRITICAL 9.8
CVE-2017-17031

A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 2…

Fix: after 4.3.3.0378
Fix from $2,300 2017-12-21
Qts CRITICAL 9.8
CVE-2017-17032

A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 2…

Fix: after 4.3.3.0378
Fix from $2,300 2017-12-21
Qts CRITICAL 9.8
CVE-2017-17033

A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 2…

Fix: after 4.3.3.0378
Fix from $2,300 2017-12-21
Qsync HIGH 7.8
CVE-2017-13070

A DLL Hijacking vulnerability in QNAP Qsync for Windows (exe) version 4.2.2.0724 and earlier could allow remote attackers to execute arbitrary code o…

Fix: after 4.2.2.0724
Fix from $1,950 2017-12-11
Video Station CRITICAL 9.8
CVE-2017-13071

QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on the QNAP Video Station 5.1.3…

Mitigation only
Fix from $2,300 2017-11-22
Music Station CRITICAL 9.8
CVE-2017-13069

QNAP discovered a number of command injection vulnerabilities found in Music Station versions 4.8.6 (for QTS 4.2.x), 5.0.7 (for QTS 4.3.x), and earli…

Fix: after 5.0.7
Fix from $2,300 2017-10-06
Qts Helpdesk HIGH 7.5
CVE-2017-13068

QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection on the application and obtain…

Fix: after 1.1.12
Fix from $1,950 2017-10-06
Qts CRITICAL 9.8
CVE-2017-10700

In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system commands as the root user of …

Mitigation only
Fix from $2,300 2017-09-19
Qts CRITICAL 9.8
CVE-2017-13067EPSS 17%

QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 and QTS 4.3.…

Fix: after 4.3.3.0299
Fix from $2,300 2017-09-14
Ts 212p Firmware CRITICAL 9.8
CVE-2017-12582

Unprivileged user can access all functions in the Surveillance Station component in QNAP TS212P devices with firmware 4.2.1 build 20160601. Unprivile…

Mitigation only
Fix from $2,300 2017-08-18
Qts CRITICAL 10.0
CVE-2017-7876

This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the is…

Fix: after 4.2.6
Fix from $2,300 2017-06-15
Qts HIGH 7.5
CVE-2017-7629

QNAP QTS before 4.2.6 build 20170517 has a flaw in the change password function.

Fix: after 4.2.6
Fix from $1,950 2017-06-15
Qts CRITICAL 9.8
CVE-2017-6359EPSS 27%

QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors.

Fix: after 4.2.4
Fix from $2,300 2017-03-23
Qts CRITICAL 9.8
CVE-2017-6360EPSS 66%

QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.

Fix: after 4.2.4
Fix from $2,300 2017-03-23
Qts CRITICAL 9.8
CVE-2017-6361EPSS 57%

QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.

Fix: after 4.2.4
Fix from $2,300 2017-03-23
Qts HIGH 7.5
CVE-2017-5227EPSS 6%

QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by reading data in an XOR forma…

Fix: after 4.2.4
Fix from $1,950 2017-03-23
Qts MEDIUM 6.1
CVE-2015-5664

Cross-site scripting (XSS) vulnerability in File Station in QNAP QTS before 4.2.0 allows remote attackers to inject arbitrary web script or HTML via …

Fix: after 4.1.4
Fix from $1,600 2016-07-03
Iartist Lite CRITICAL 9.8
CVE-2015-7261

The FTP service in QNAP iArtist Lite before 1.4.54, as distributed with QNAP Signage Station before 2.0.1, has hardcoded credentials, which makes it …

Fix: after 2.0
Fix from $2,300 2016-02-27
Iartist Lite HIGH 7.5
CVE-2015-7262

QNAP iArtist Lite before 1.4.54, as distributed with QNAP Signage Station before 2.0.1, allows remote authenticated users to gain privileges by regis…

Fix: after 2.0
Fix from $1,950 2016-02-27
Sinage Station HIGH 7.5
CVE-2015-6036

QNAP Signage Station before 2.0.1 allows remote attackers to bypass authentication, and consequently upload files, via a spoofed HTTP request.

Mitigation only
Fix from $1,950 2016-02-27
Signage Station HIGH 8.8
CVE-2015-6022

Unrestricted file upload vulnerability in QNAP Signage Station before 2.0.1 allows remote authenticated users to execute arbitrary code by uploading …

Fix: after 2.0
Fix from $1,950 2016-02-27
Qts HIGH 9.3
CVE-2015-6003

Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attac…

Fix: after 4.2.0
Fix from $1,950 2015-10-16
Photo Station Firmware MEDIUM 5.0
CVE-2013-5760

QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to photo/p/api/list.php.

Fix: after 4.0.3
Fix from $1,600 2014-06-09
Qts HIGH 7.8
CVE-2013-7174

Absolute path traversal vulnerability in cgi-bin/jc.cgi in QNAP QTS before 4.1.0 allows remote attackers to read arbitrary files via a full pathname …

Fix: after 4.0.3
Fix from $1,950 2014-01-09
Viostor Network Video Recorder MEDIUM 6.8
CVE-2013-0144

Cross-site request forgery (CSRF) vulnerability in cgi-bin/create_user.cgi on QNAP VioStor NVR devices with firmware 4.0.3 allows remote attackers to…

Mitigation only
Fix from $1,600 2013-06-07
Viostor Network Video Recorder MEDIUM 6.5
CVE-2013-0143EPSS 7%

cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authen…

Mitigation only
Fix from $1,600 2013-06-07
Viostor Network Video Recorder MEDIUM 5.0
CVE-2013-0142

QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows re…

Mitigation only
Fix from $1,600 2013-06-07
Ts 239 Pro Turbo Nas MEDIUM 5.9
CVE-2009-3200

The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create an undocumented recovery key and store it in the ENCK …

No fix yet
Fix from $1,600 2009-09-21
Ts 239 Pro Firmware MEDIUM 5.5
CVE-2009-3278

The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 use the rand library function to generate a certain recovery …

No fix yet
Fix from $1,600 2009-09-21