Vulnerability index

Browse CVEs

539 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

File Station CRITICAL 9.1
CVE-2026-26241

A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory …

Fix: 5.5.6.5243+
Fix from $2,300 2026-06-10
File Station CRITICAL 9.1
CVE-2026-26240

A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory …

Fix: 5.5.6.5243+
Fix from $2,300 2026-06-10
File Station HIGH 8.1
CVE-2026-26239

A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vuln…

Fix: 5.5.6.5208+
Fix from $1,950 2026-06-10
Qumagie HIGH 7.5
CVE-2026-26237

A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthor…

Fix: 2.9.0+
Fix from $1,950 2026-06-10
File Station HIGH 8.1
CVE-2026-24724

An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit…

Fix: 5.5.6.5243+
Fix from $1,950 2026-06-10
Qts HIGH 7.2
CVE-2026-24719

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator acc…

Fix: 5.2.9.3492+
Fix from $1,950 2026-06-10
File Station MEDIUM 6.5
CVE-2026-24720

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a remote attacker gains a user a…

Fix: 5.5.6.5243+
Fix from $1,600 2026-06-10
Qts HIGH 7.2
CVE-2026-24716

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administra…

Fix: 5.2.9.3492+
Fix from $1,950 2026-06-10
File Station MEDIUM 6.5
CVE-2026-22899

A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit…

Fix: 5.5.6.5208+
Fix from $1,600 2026-06-10
Qts MEDIUM 6.5
CVE-2026-24717

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator accoun…

Fix: 5.2.9.3492+
Fix from $1,600 2026-06-10
Qts HIGH 7.2
CVE-2025-66281

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit th…

Fix: 5.2.9.3410+
Fix from $1,950 2026-06-10
Qts HIGH 7.2
CVE-2026-22893

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator acc…

Fix: 5.2.9.3410+
Fix from $1,950 2026-06-10
Qts HIGH 7.2
CVE-2025-66273

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator acc…

Fix: 5.2.9.3410+
Fix from $1,950 2026-06-10
Qts HIGH 7.2
CVE-2025-66279

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator acc…

Fix: 5.2.9.3410+
Fix from $1,950 2026-06-10
Qts HIGH 7.2
CVE-2025-66280

An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an adm…

Fix: 5.2.9.3410+
Fix from $1,950 2026-06-10
Quts Hero HIGH 7.2
CVE-2025-62850

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administra…

Mitigation only
Fix from $1,950 2026-06-10
Qts CRITICAL 9.8
CVE-2025-66276

QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later

Fix: 5.2.7.3256+
Fix from $2,300 2026-06-10
Notification Center HIGH 8.8
CVE-2025-58468

A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerab…

Fix: 1.10.0.3291+
Fix from $1,950 2026-06-10
Qumagie CRITICAL 9.8
CVE-2026-44083

An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vuln…

Fix: 2.9.0+
Fix from $2,300 2026-06-09
Qts MEDIUM 6.5
CVE-2025-62858

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator accou…

Mitigation only
Fix from $1,600 2026-06-09
Qts MEDIUM 6.1
CVE-2026-41539

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit …

Mitigation only
Fix from $1,600 2026-06-09
Qumagie HIGH 7.5
CVE-2026-26236

A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthor…

Fix: 2.9.0+
Fix from $1,950 2026-06-09
Qunetswitch CRITICAL 9.8
CVE-2026-22897

A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to execute arbitra…

Fix: 2.0.4.0415+
Fix from $2,300 2026-03-20
Qvr Pro CRITICAL 9.8
CVE-2026-22898

A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerabi…

Fix: 2.7.4.1485+
Fix from $2,300 2026-03-20
Qunetswitch CRITICAL 9.8
CVE-2026-22900

A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to gai…

Fix: 2.0.5.0906+
Fix from $2,300 2026-03-20
Qunetswitch CRITICAL 9.8
CVE-2026-22901

A command injection vulnerability has been reported to affect QuNetSwitch. If a remote attacker gains a user account, they can then exploit the vulne…

Fix: after 2.0.5.0906
Fix from $2,300 2026-03-20
Qunetswitch MEDIUM 6.7
CVE-2026-22902

A command injection vulnerability has been reported to affect QuNetSwitch. If a local attacker gains an administrator account, they can then exploit …

Fix: after 2.0.5.0906
Fix from $1,600 2026-03-20
Qurouter MEDIUM 6.7
CVE-2025-62846

An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulne…

Mitigation only
Fix from $1,600 2026-03-20
Media Streaming Add On CRITICAL 9.1
CVE-2025-59383

A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploit the vulnerability to modify…

Fix: 500.1.1.0+
Fix from $2,300 2026-03-20
Qurouter MEDIUM 6.8
CVE-2025-62843

An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. If an attacker gains physical…

Mitigation only
Fix from $1,600 2026-03-20