Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

5328 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.1QNAP

Medium [CVE-2020-2491] QTS: This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code.

This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. QTS 4.5.1: Photo Station 6.0.12 and later QTS 4.4.3: Photo Station 6.0.12 and later QTS 4.3.6: Photo Station 5.7.12 and later QTS 4.3.4: Photo Station 5.7.13 and later QTS 4.3.3: Photo Station 5.4.10 and later QTS 4.2.6: Photo Station 5.2.11 and later

CVE-2020-2491
Unclassified
Dec 10, 2020
High7.2QNAP

High [CVE-2020-2492] QTS: If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands.

If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.

CVE-2020-2492
Unclassified
Nov 16, 2020
Critical9.8QNAP

Critical [CVE-2018-19950] Music Station: If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands.

If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.

CVE-2018-19950
Unclassified
Nov 2, 2020
High7.5QNAP

High [CVE-2018-19952] Music Station: If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information.

If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.

CVE-2018-19952
Unclassified
Nov 2, 2020
Medium6.1QNAP

Medium [CVE-2018-19956] Photo Station: The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station.

The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc.

CVE-2018-19956
Unclassified
Nov 2, 2020
Medium6.1QNAP

Medium [CVE-2018-19951] Music Station: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.

CVE-2018-19951
Unclassified
Nov 2, 2020
Critical9.8QNAP Exploited CISA KEV

Critical [CVE-2018-19949] QTS: If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands.

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

CVE-2018-19949
Unclassified
Oct 28, 2020
High8.0QNAP Exploited CISA KEV

High [CVE-2018-19943] QTS: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later

CVE-2018-19943
Unclassified
Oct 28, 2020
Medium6.1QNAP Exploited CISA KEV

Medium [CVE-2018-19953] QTS: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

CVE-2018-19953
Unclassified
Oct 28, 2020
High7.5Ubiquiti

High [CVE-2020-27888] issue was discovered on Ubiquiti UniFi Meshing Access Point UAP-AC-M 4.3.21.11325 and UniFi Controller 6.0.28 devices

An issue was discovered on Ubiquiti UniFi Meshing Access Point UAP-AC-M 4.3.21.11325 and UniFi Controller 6.0.28 devices. Cached credentials are not erased from an access point returning wirelessly from a disconnected state. This may provide unintended network access.

CVE-2020-27888
Unclassified
Oct 27, 2020
Medium4.3QNAP

Medium [CVE-2018-19947] Helpdesk: The vulnerability have been reported to affect earlier versions of Helpdesk.

The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sensitive information. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.

CVE-2018-19947
Unclassified
Sep 11, 2020
Medium4.2QNAP

Medium [CVE-2018-19946] Helpdesk: The vulnerability have been reported to affect earlier versions of Helpdesk.

The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.

CVE-2018-19946
Unclassified
Sep 11, 2020
Low2.0QNAP

Low [CVE-2018-19948] Helpdesk: The vulnerability have been reported to affect earlier versions of Helpdesk.

The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could allow attackers to force NAS users to execute unintentional actions through a web application. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.

CVE-2018-19948
Unclassified
Sep 11, 2020
Critical9.8QNAP

Critical [CVE-2020-2500] Helpdesk: This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service.

This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive data on QNAP Kayako server with API keys. We have replaced the API key to mitigate the vulnerability, and already fixed the issue in Helpdesk 3.0.1 and later versions.

CVE-2020-2500
Unclassified
Jul 1, 2020
Medium5.4pfSense

Medium [CVE-2020-11457] pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI

pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full name) of a user.

CVE-2020-11457
Unclassified
Apr 1, 2020
Medium5.3Proxmox

Medium [CVE-2014-4156] Proxmox VE: Proxmox VE prior to 3.2: 'AccessControl.pm' User Enumeration Vulnerability

Proxmox VE prior to 3.2: 'AccessControl.pm' User Enumeration Vulnerability

CVE-2014-4156
Unclassified
Jan 27, 2020
Critical9.8QNAP Exploited CISA KEV

Critical [CVE-2019-7195] Photo Station: This external control of file name or path vulnerability allows remote attackers to access or modify system files.

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

CVE-2019-7195
Unclassified
Dec 5, 2019
Critical9.8QNAP Exploited CISA KEV

Critical [CVE-2019-7193] QTS: This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system.

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

CVE-2019-7193
Unclassified
Dec 5, 2019
Critical9.8QNAP Exploited CISA KEV

Critical [CVE-2019-7192] Photo Station: This improper access control vulnerability allows remote attackers to gain unauthorized access to the system.

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.

CVE-2019-7192
Unclassified
Dec 5, 2019
Critical9.8QNAP

Critical [CVE-2019-7183] QTS: This improper link resolution vulnerability allows remote attackers to access system files.

This improper link resolution vulnerability allows remote attackers to access system files. To fix this vulnerability, QNAP recommend updating QTS to their latest versions.

CVE-2019-7183
Unclassified
Dec 5, 2019