qnap

613 tracked vulnerabilities.

CVE-2021-44055 MEDIUM
QNAP Video Station < 5.1.8 - Missing Authorization
May 05, 2022
CVSS 5.3
EPSS 0.01
CVE-2021-44054 MEDIUM
QNAP QTS 4.3.3-5.0.0, QuTS hero <4.5.4.1771, QuTScloud <5.0.1.1998 Open Redirect
May 05, 2022
CVSS 4.3
EPSS 0.00
CVE-2021-44053 MEDIUM
QNAP QTS 4.3.3-5.0.0, QuTS hero <4.5.4.1771, QuTScloud <5.0.1.1998 - XSS
May 05, 2022
CVSS 5.7
EPSS 0.00
CVE-2021-44052 MEDIUM
QNAP QTS 4.3.3-5.0.0, QuTS hero <4.5.4.1971, QuTScloud <5.0.1.1998 Path Traversal
May 05, 2022
CVSS 6.5
EPSS 0.00
CVE-2021-44051 HIGH
QNAP QTS 4.3.3-5.0.0, QuTS hero <4.5.4.1771, QuTScloud <5.0.1.1998 - Remote Command Injection
May 05, 2022
CVSS 8.8
EPSS 0.01
CVE-2021-38693 MEDIUM
QNAP QTS < 4.5.4.1991 and QuTS hero < h5.0.0.1949 and QuTScloud < c5.0.1.1949 - Path Traversal
May 05, 2022
CVSS 5.3
EPSS 0.00
CVE-2021-34361 MEDIUM
QNAP NAS Proxy Server < 1.4.2 - Cross-Site Scripting
Feb 25, 2022
CVSS 5.3
EPSS 0.00
CVE-2021-34359 MEDIUM
QNAP NAS Proxy Server < 1.4.2 - Cross-Site Scripting
Feb 25, 2022
CVSS 6.9
EPSS 0.00
CVE-2021-38679 MEDIUM
QNAP Kazoo Server < 4.11.22 - Improper Authentication
Feb 11, 2022
CVSS 6.5
EPSS 0.00
CVE-2021-38692 HIGH
QNAP QVR Elite < 2.1.4.0, QVR Pro < 2.1.3.0, QVR Guard < 2.1.3.0 - Remote Code Execution
Jan 14, 2022
CVSS 8.1
EPSS 0.01
CVE-2021-38691 HIGH
QNAP QVR Elite < 2.1.4.0, QVR Pro < 2.1.3.0, QVR Guard < 2.1.3.0 - Remote Code Execution
Jan 14, 2022
CVSS 8.1
EPSS 0.01
CVE-2021-38690 HIGH
QNAP QVR Elite < 2.1.4.0, QVR Pro < 2.1.3.0, QVR Guard < 2.1.3.0 - Remote Code Execution
Jan 14, 2022
CVSS 8.1
EPSS 0.01
CVE-2021-38689 HIGH
QNAP QVR Elite < 2.1.4.0, QVR Pro < 2.1.3.0, QVR Guard < 2.1.3.0 - Remote Code Execution
Jan 14, 2022
CVSS 8.1
EPSS 0.01
CVE-2021-38682 HIGH
QNAP QVR Elite < 2.1.4.0, QVR Pro < 2.1.3.0, QVR Guard < 2.1.3.0 - Remote Code Execution
Jan 14, 2022
CVSS 8.1
EPSS 0.01
CVE-2021-38678 MEDIUM
QNAP QcalAgent <1.1.7 - Open Redirect
Jan 14, 2022
CVSS 6.1
EPSS 0.00
CVE-2021-38677 MEDIUM
QcalAgent < 1.1.7 - Cross-Site Scripting
Jan 14, 2022
CVSS 5.3
EPSS 0.00
CVE-2021-38674 MEDIUM
QTS, QuTS hero, QuTScloud <4.5.4.1771 - XSS
Jan 07, 2022
CVSS 4.2
EPSS 0.00
CVE-2021-38688 HIGH
Android App Qfile <3.0.0.1105 - Auth Bypass
Dec 29, 2021
CVSS 7.1
EPSS 0.00
CVE-2021-38687 HIGH
QNAP Surveillance Station < 5.2.0.4.2 - Remote Code Execution via Stack Buffer Overflow
Dec 29, 2021
CVSS 8.1
EPSS 0.01
CVE-2021-38680 MEDIUM
Kazoo Server < 4.11.20 - Cross-Site Scripting
Dec 29, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-38686 HIGH
QVR < 5.1.6 - Improper Authentication
Nov 26, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-38685 CRITICAL
QVR < 5.1.6 - OS Command Injection
Nov 26, 2021
CVSS 9.8
EPSS 0.01
CVE-2021-38681 MEDIUM
QNAP Ragic Cloud DB < 3.7.0.1 - Reflected Cross-Site Scripting
Nov 20, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-34358 MEDIUM
QmailAgent < 3.0.2 - Cross-Site Request Forgery
Nov 20, 2021
CVSS 6.8
EPSS 0.00
CVE-2021-38684 HIGH
QNAP Multimedia Console < 1.4.3 - Remote Code Execution via Stack Buffer Overflow
Nov 13, 2021
CVSS 8.1
EPSS 0.01