CVE-2021-28806
- EPSS 0.25%
- Veröffentlicht 03.06.2021 03:15:08
- Zuletzt bearbeitet 21.11.2024 06:00:14
A DOM-based XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.3.1652 Build 202...
CVE-2021-28798
- EPSS 0.4%
- Veröffentlicht 21.05.2021 03:15:09
- Zuletzt bearbeitet 21.11.2024 06:00:13
A relative path traversal vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to modify files that impact system integrity. QNAP have already fixed this vulnerability in the ...
CVE-2020-2509
- EPSS 74.04%
- Veröffentlicht 17.04.2021 04:15:11
- Zuletzt bearbeitet 13.02.2025 14:22:58
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following v...
CVE-2020-36195
- EPSS 2.02%
- Veröffentlicht 17.04.2021 04:15:11
- Zuletzt bearbeitet 21.11.2024 05:28:59
An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulne...
CVE-2018-19942
- EPSS 0.27%
- Veröffentlicht 16.04.2021 01:15:12
- Zuletzt bearbeitet 21.11.2024 03:58:51
A cross-site scripting (XSS) vulnerability has been reported to affect earlier versions of File Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following vers...
CVE-2020-2508
- EPSS 2.46%
- Veröffentlicht 11.01.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:25:23
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following...
CVE-2018-19941
- EPSS 0.15%
- Veröffentlicht 31.12.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 03:58:51
A vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows an attacker to access sensitive information stored in cleartext inside cookies via certain widely-available tools. QNAP have already fixed this vulnerabilit...
CVE-2018-19944
- EPSS 0.15%
- Veröffentlicht 31.12.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 03:58:51
A cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices. If exploited, this vulnerability allows a remote attacker to gain access to sensitive information. QNAP have already fixed this vulnerabi...
CVE-2018-19945
- EPSS 0.4%
- Veröffentlicht 31.12.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 03:58:51
A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitations of a pathname to a restricted directory, this vulnerability allows for renaming arbitrary files on the target system, if explo...
CVE-2020-25847
- EPSS 3.85%
- Veröffentlicht 29.12.2020 07:15:13
- Zuletzt bearbeitet 21.11.2024 05:18:53
This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero.