Qnap
qnap
635 CVEs • 143 products
Products (143)
Click to collapseToggle
Products (143)
Click to collapse
CVEs (635)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qnap 2Iartist Lite Signage StationMay 6, 2026 Feb 27, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The FTP service in QNAP iArtist Lite before 1.4.54, as distributed with QNAP Signage Station before 2.0.1, has hardcoded credentials, which makes it easier for remote attackers to obtain access via a session on TCP port...Show more |
QNAP Signage Station before 2.0.1 allows remote attackers to bypass authentication, and consequently upload files, via a spoofed HTTP request. |
Unrestricted file upload vulnerability in QNAP Signage Station before 2.0.1 allows remote authenticated users to execute arbitrary code by uploading an executable file, and then accessing this file via an unspecified URL...Show more |
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS...Show more |
17Apple AristaCanonical+14 more74Arx Firmware BashBig Ip Access Policy Manager+71 moreApr 22, 2026 Sep 25, 2014 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown oth...Show more |
17Apple AristaCanonical+14 more74Arx Firmware BashBig Ip Access Policy Manager+71 moreApr 22, 2026 Sep 24, 2014 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vec...Show more |
1Qnap 8Ss 839 Ss 839 FirmwareTs 459u+5 moreMay 6, 2026 Aug 25, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 QNAP TS-469U with firmware 4.0.7 Build 20140410, TS-459U, TS-EC1679U-RP, and SS-839 use world-readable permissions for /etc/config/shadow, which allows local users to obtain usernames and hashed passwords by reading the...Show more |
1Qnap 2Photo Station Photo Station FirmwareMay 6, 2026 Jun 9, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to photo/p/api/list.php. |
Absolute path traversal vulnerability in cgi-bin/jc.cgi in QNAP QTS before 4.1.0 allows remote attackers to read arbitrary files via a full pathname in the f parameter. |
1Qnap 1Viostor Network Video Recorder Apr 29, 2026 Jun 7, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in cgi-bin/create_user.cgi on QNAP VioStor NVR devices with firmware 4.0.3 allows remote attackers to hijack the authentication of administrators for requests that create a...Show more |
1Qnap 3Nas Surveillance Station ProViostor Network Video RecorderApr 29, 2026 Jun 7, 2013 N/A· v4 N/A· v3 6.5 MEDIUM· v2 cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access...Show more |
1Qnap 3Nas Surveillance Station ProViostor Network Video RecorderApr 29, 2026 Jun 7, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows remote attackers to obtain web-server login access via unspecified vector...Show more |
1Qnap 2Ts 239 Pro Turbo Nas Ts 639 Pro Turbo NasApr 23, 2026 Sep 21, 2009 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create a LUKS partition by using the AES-256 cipher in plain CBC mode, which allows local users to obtain sensitive information via...Show more |
1Qnap 2Ts 239 Pro Firmware Ts 639 Pro FirmwareApr 23, 2026 Sep 21, 2009 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 use the rand library function to generate a certain recovery key, which makes it easier for local users to determine this key via a...Show more |
1Qnap 2Ts 239 Pro Turbo Nas Ts 639 Pro Turbo NasApr 23, 2026 Sep 21, 2009 N/A· v4 N/A· v3 5.9 MEDIUM· v2 The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create an undocumented recovery key and store it in the ENCK variable in flash memory, which allows local users to bypass the passph...Show more |