Vulnerability index

Browse CVEs

539 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.7 CVE-2018-0721 Buffer Overflow vulnerability in NAS devices. QTS allows attackers to run arbitrary code. This issue affects: QNAP Systems Inc. QTS version 4.2.6 and… Qts Mitigation only Fix from $1,9502018-11-27 MEDIUM 5.5 CVE-2018-0719 Cross-site Scripting (XSS) vulnerability in NAS devices of QNAP Systems Inc. QTS allows attackers to inject javascript. This issue affects: QNAP Syst… Qts Mitigation only Fix from $1,6002018-11-27 CRITICAL 9.8 CVE-2018-0718 Command injection vulnerability in Music Station 5.1.2 and earlier versions in QNAP QTS 4.3.3 and 4.3.4 could allow remote attackers to run arbitrary… Music Station after 5.1.2 Fix from $2,3002018-09-14 MEDIUM 6.1 CVE-2018-0715 Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the com… Photo Station after 5.7.0 Fix from $1,6002018-08-27 CRITICAL 9.8 CVE-2018-0714 Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 2… Helpdesk after 1.1.21 Fix from $2,3002018-08-13 HIGH 8.8 CVE-2018-0708EPSS 26% Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run … Q\'center after 1.7.1063 Fix from $1,9502018-07-17 HIGH 8.8 CVE-2018-0709EPSS 14% Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitr… Q\'center after 1.7.1063 Fix from $1,9502018-07-17 HIGH 8.8 CVE-2018-0710EPSS 14% Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitra… Q\'center after 1.7.1063 Fix from $1,9502018-07-17 HIGH 7.2 CVE-2018-0707EPSS 59% Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to… Q\'center after 1.7.1063 Fix from $1,9502018-07-17 HIGH 8.8 CVE-2018-0706EPSS 49% Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to access sensitive i… Q\'center after 1.7.1063 Fix from $1,9502018-07-17 CRITICAL 9.8 CVE-2018-0712 Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 and their earlier… Qts after 4.3.4 Fix from $2,3002018-06-21 MEDIUM 6.1 CVE-2017-13072 Cross-site scripting (XSS) vulnerability in App Center in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20171213, QTS 4.3.4 build 20171223, and thei… Qts Mitigation only Fix from $1,6002018-06-21 CRITICAL 9.8 CVE-2017-7637 QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to run arbitrary OS commands against the system with root privileges. Nas Proxy Server 1.3.0+ Fix from $2,3002018-06-05 HIGH 8.8 CVE-2017-7635 QNAP NAS application Proxy Server through version 1.2.0 does not utilize CSRF protections. Nas Proxy Server 1.3.0+ Fix from $1,9502018-06-05 MEDIUM 6.1 CVE-2017-7636 Cross-site scripting (XSS) vulnerability in QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to inject arbitrary web s… Nas Proxy Server 1.3.0+ Fix from $1,6002018-06-05 MEDIUM 5.3 CVE-2017-7639 QNAP NAS application Proxy Server through version 1.2.0 does not authenticate requests properly. Successful exploitation can lead to change of the se… Nas Proxy Server 1.3.0+ Fix from $1,6002018-06-05 MEDIUM 6.1 CVE-2018-0711 Cross-site scripting (XSS) vulnerability in QNAP QTS 4.3.3 build 20180126, QTS 4.3.4 build 20180315, and their earlier versions could allow remote at… Qts Mitigation only Fix from $1,6002018-04-30 MEDIUM 6.1 CVE-2017-13073 Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote a… Photo Station after 5.4.3 Fix from $1,6002018-04-23 MEDIUM 6.1 CVE-2017-7631 Cross-site scripting (XSS) vulnerability in the share link function of File Station of QNAP 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlie… Qts Mitigation only Fix from $1,6002018-03-27 MEDIUM 6.1 CVE-2017-7632 Cross-site scripting (XSS) vulnerability in File Station of QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attacke… Qts Mitigation only Fix from $1,6002018-03-27 MEDIUM 5.3 CVE-2017-7630 QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensitive information (firmware ver… Qts Mitigation only Fix from $1,6002018-03-27 CRITICAL 9.8 CVE-2017-7640 QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against th… Media Streaming Add On after 430.1.2.0 Fix from $2,3002018-03-08 HIGH 8.8 CVE-2017-7641 QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not utilize CSRF protections. Media Streaming Add On after 430.1.2.0 Fix from $1,9502018-03-08 MEDIUM 6.5 CVE-2017-7638 QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitatio… Media Streaming Add On after 430.1.2.0 Fix from $1,6002018-03-08 MEDIUM 6.1 CVE-2017-7634 Cross-site scripting (XSS) vulnerability in QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attac… Media Streaming Add On after 430.1.2.0 Fix from $1,6002018-03-08 HIGH 7.5 CVE-2017-7633 QNAP Qfinder Pro 6.1.0.0317 and earlier may expose sensitive information contained in NAS devices. If exploited, this may allow attackers to further … Qfinder Pro after 6.1.0.0317 Fix from $1,9502018-03-05 CRITICAL 9.8 CVE-2017-17027 A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 2017111… Qts after 4.3.3.0378 Fix from $2,3002017-12-21 CRITICAL 9.8 CVE-2017-17028 A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) … Qts after 4.3.3.0378 Fix from $2,3002017-12-21 CRITICAL 9.8 CVE-2017-17029 A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 2017… Qts after 4.3.3.0378 Fix from $2,3002017-12-21 CRITICAL 9.8 CVE-2017-17030 A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 2017… Qts after 4.3.3.0378 Fix from $2,3002017-12-21