Vulnerability index

Browse CVEs

539 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Qts CRITICAL 9.8
CVE-2025-62849

An SQL injection vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerab…

Mitigation only
Fix from $2,300 2025-12-16
Qts HIGH 7.5
CVE-2025-62847

An improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP operating system versions. The …

Mitigation only
Fix from $1,950 2025-12-16
Qts HIGH 7.5
CVE-2025-62848

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit th…

Mitigation only
Fix from $1,950 2025-12-16
Photo Station CRITICAL 9.8
CVE-2017-20210

Photo Station 5.4.1 & 5.2.7 include the security fix for the vulnerability related to the XMR mining programs identified by internal research.

Mitigation only
Fix from $2,300 2025-11-11
Qulog Center HIGH 8.8
CVE-2025-58469

A cross-site request forgery (CSRF) vulnerability has been reported to affect QuLog Center. The remote attackers can then exploit the vulnerability t…

Fix: 1.8.2.923+
Fix from $1,950 2025-11-07
Qumagie HIGH 7.5
CVE-2025-58464

A relative path traversal vulnerability has been reported to affect QuMagie. If a remote attacker, they can then exploit the vulnerability to read th…

Fix: 2.7.3+
Fix from $1,950 2025-11-07
Download Station MEDIUM 5.4
CVE-2025-58465

A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a remote attacker gains a user account, they can then exp…

Fix: 5.10.0.305+
Fix from $1,600 2025-11-07
Qsync Central MEDIUM 6.5
CVE-2025-57712

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulner…

Fix: 5.0.0.3+
Fix from $1,600 2025-11-07
File Station MEDIUM 5.4
CVE-2025-57706

A cross-site scripting (XSS) vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then explo…

Fix: 5.5.6.5018+
Fix from $1,600 2025-11-07
File Station MEDIUM 6.5
CVE-2025-53408

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit…

Fix: 5.5.6.5018+
Fix from $1,600 2025-11-07
File Station MEDIUM 6.5
CVE-2025-53409

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a…

Fix: 5.5.6.5018+
Fix from $1,600 2025-11-07
File Station MEDIUM 6.5
CVE-2025-53410

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a…

Fix: 5.5.6.5018+
Fix from $1,600 2025-11-07
File Station MEDIUM 6.5
CVE-2025-53412

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit…

Fix: 5.5.6.5018+
Fix from $1,600 2025-11-07
File Station MEDIUM 6.5
CVE-2025-53413

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a…

Fix: 5.5.6.5018+
Fix from $1,600 2025-11-07
Qumagie CRITICAL 9.8
CVE-2025-52425

An SQL injection vulnerability has been reported to affect QuMagie. A remote attacker can exploit the vulnerability to execute unauthorized code or c…

Fix: 2.7.0+
Fix from $2,300 2025-11-07
File Station MEDIUM 6.5
CVE-2025-47207

A NULL pointer dereference vulnerability has been reported to affect several product versions. If a remote attacker gains a user account, they can th…

Fix: 5.5.6.5018+
Fix from $1,600 2025-11-07
File Station MEDIUM 6.5
CVE-2025-52865

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit…

Fix: 5.5.6.5018+
Fix from $1,600 2025-11-07
Netbak Replicator HIGH 7.8
CVE-2025-57714

An unquoted search path or element vulnerability has been reported to affect NetBak Replicator. If a local attacker gains a user account, they can th…

Fix: 4.5.15.0807+
Fix from $1,950 2025-10-03
Authenticator MEDIUM 6.8
CVE-2025-54154

An improper authentication vulnerability has been reported to affect QNAP Authenticator. If an attacker gains physical access, they can then exploit …

Fix: 1.3.1.1227+
Fix from $1,600 2025-10-03
Qsync Central HIGH 8.8
CVE-2025-53595

An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulner…

Fix: 5.0.0.2+
Fix from $1,950 2025-10-03
Qsync Central HIGH 8.8
CVE-2025-54153

An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulner…

Fix: 5.0.0.2+
Fix from $1,950 2025-10-03
Qsync Central MEDIUM 6.5
CVE-2025-52867

An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can the…

Fix: 5.0.0.2+
Fix from $1,600 2025-10-03
Qts MEDIUM 6.5
CVE-2025-53406

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker g…

Mitigation only
Fix from $1,600 2025-10-03
Qts MEDIUM 6.5
CVE-2025-53407

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker g…

Mitigation only
Fix from $1,600 2025-10-03
Qts MEDIUM 6.5
CVE-2025-48730

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker g…

Mitigation only
Fix from $1,600 2025-10-03
Qts MEDIUM 6.5
CVE-2025-52429

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker g…

Mitigation only
Fix from $1,600 2025-10-03
Qsync Central HIGH 8.8
CVE-2025-44014

An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Fix: 5.0.0.1+
Fix from $1,950 2025-10-03
Qts HIGH 7.2
CVE-2025-47212

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator acc…

Mitigation only
Fix from $1,950 2025-10-03
Qsync Central MEDIUM 6.5
CVE-2025-47210

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit …

Fix: 5.0.0.2+
Fix from $1,600 2025-10-03
Qsync Central MEDIUM 6.5
CVE-2025-44008

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit …

Fix: 5.0.0.1+
Fix from $1,600 2025-10-03