← Back

Qnap

qnap

635 CVEs • 143 products

Products (143)

Click to collapse
Toggle
Qts
qts
Quts Hero
quts_hero
Qutscloud
qutscloud
Qsync Central
qsync_central
File Station
file_station
Photo Station
photo_station
Video Station
video_station
Music Station
music_station
Qumagie
qumagie
Qurouter
qurouter
Helpdesk
helpdesk
Qvr
qvr
Qulog Center
qulog_center
Q'center
q'center
Qvr Pro
qvr_pro
Qunetswitch
qunetswitch
Qvr Elite
qvr_elite
Qvr Guard
qvr_guard
Qes
qes
Qcalagent
qcalagent
Qvpn
qvpn
Qufirewall
qufirewall
Nas
nas
Iartist Lite
iartist_lite
Myqnapcloud
myqnapcloud
Qss
qss
Qusbcam2
qusbcam2
Qmailagent
qmailagent
Kazoo Server
kazoo_server
Ts 469u
ts-469u
Ts Ec1679u Rp
ts-ec1679u-rp
Ts 459u
ts-459u
Ss 839
ss-839
Sinage Station
sinage_station
Qts Helpdesk
qts_helpdesk
Qsync
qsync
Qfinder Pro
qfinder_pro
Roon Server
roon_server
Image2pdf
image2pdf
Ragic Cloud Db
ragic_cloud_db
Qfile
qfile
Qvr Pro Client
qvr_pro_client
Qvr Firmware
qvr_firmware
Ai Core
ai_core

CVEs (635)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qnap
1Qts
Nov 21, 2024
Dec 4, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
1Qnap
1Music Station
Nov 21, 2024
Dec 4, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating Music Station to their latest versions.
1Qnap
1Helpdesk
Nov 21, 2024
Dec 4, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerability, QNAP recommend updating QTS and Helpdesk to their latest versions.
1Qnap
1Myqnapcloud
Jun 17, 2026
May 9, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Buffer Overflow vulnerability in myQNAPcloud Connect 1.3.3.0925 and earlier could allow remote attackers to crash the program.
1Qnap
1Photo Station
Nov 21, 2024
Feb 1, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier in QTS 4.2.6 could allow remote attackers to access sensitive information on the d...Show more
Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier in QTS 4.2.6 could allow remote attackers to access sensitive information on the device.Show less
1Qnap
1Q'center Virtual Appliance
Nov 21, 2024
Dec 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote attackers to inject Javascript code in the compromised application, a different vulnerability than C...Show more
Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote attackers to inject Javascript code in the compromised application, a different vulnerability than CVE-2018-0723.Show less
1Qnap
1Q'center Virtual Appliance
Nov 21, 2024
Dec 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote attackers to inject Javascript code in the compromised application, a different vulnerability than C...Show more
Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote attackers to inject Javascript code in the compromised application, a different vulnerability than CVE-2018-0724.Show less
1Qnap
1Qts
Nov 21, 2024
Nov 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in QTS 4.2.6 build 20180711, QTS 4.3.3: Qsync Central 3.0.2, QTS 4.3.4: Qsync Central 3.0.3, QTS 4.3.5: Qsync Central 3.0.4 and earlier versions could allow remote attackers to inject J...Show more
Cross-site scripting vulnerability in QTS 4.2.6 build 20180711, QTS 4.3.3: Qsync Central 3.0.2, QTS 4.3.4: Qsync Central 3.0.3, QTS 4.3.5: Qsync Central 3.0.4 and earlier versions could allow remote attackers to inject Javascript code in the compromised application.Show less
1Qnap
1Qts
Nov 21, 2024
Nov 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buffer Overflow vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could have unspecified impact on the NAS.
1Qnap
1Qts
Nov 21, 2024
Nov 28, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to power off the NAS.
1Qnap
1Qts
Nov 21, 2024
Nov 28, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to crash the NAS media se...Show more
NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to crash the NAS media server.Show less
1Qnap
1Qts
Nov 21, 2024
Nov 28, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to run arbitrary commands on the...Show more
Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to run arbitrary commands on the NAS.Show less
1Qnap
1Qts
Nov 21, 2024
Nov 27, 2018
N/A· v4
7.7 HIGH· v3
10.0 HIGH· v2
Buffer Overflow vulnerability in NAS devices. QTS allows attackers to run arbitrary code. This issue affects: QNAP Systems Inc. QTS version 4.2.6 and prior versions on build 20180711; version 4.3.3 and prior versions on...Show more
Buffer Overflow vulnerability in NAS devices. QTS allows attackers to run arbitrary code. This issue affects: QNAP Systems Inc. QTS version 4.2.6 and prior versions on build 20180711; version 4.3.3 and prior versions on build 20180725; version 4.3.4 and prior versions on build 20180710.Show less
1Qnap
1Qts
Nov 21, 2024
Nov 27, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) vulnerability in NAS devices of QNAP Systems Inc. QTS allows attackers to inject javascript. This issue affects: QNAP Systems Inc. QTS version 4.2.6 and prior versions on build 20180711; versio...Show more
Cross-site Scripting (XSS) vulnerability in NAS devices of QNAP Systems Inc. QTS allows attackers to inject javascript. This issue affects: QNAP Systems Inc. QTS version 4.2.6 and prior versions on build 20180711; version 4.3.3 and prior versions on build 20180725; version 4.3.4 and prior versions on build 20180710.Show less
1Qnap
1Music Station
Nov 21, 2024
Sep 14, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Command injection vulnerability in Music Station 5.1.2 and earlier versions in QNAP QTS 4.3.3 and 4.3.4 could allow remote attackers to run arbitrary commands in the compromised application.
1Qnap
1Photo Station
Nov 21, 2024
Aug 27, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application.
1Qnap
1Helpdesk
Nov 21, 2024
Aug 13, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 20180528 and their earlier versions could allow remote attackers to run...Show more
Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 20180528 and their earlier versions could allow remote attackers to run arbitrary commands in the compromised application.Show less
1Qnap
1Q'center
Nov 21, 2024
Jul 17, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.
1Qnap
1Q'center
Nov 21, 2024
Jul 17, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.
1Qnap
1Q'center
Nov 21, 2024
Jul 17, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.