Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

106 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.8QNAP

High [CVE-2024-50404] Qsync: link following vulnerability has been reported to affect Qsync Central.

A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.16_20240819 ( 2024/08/19 ) and later

CVE-2024-50404
Applications
Dec 6, 2024
High7.2QNAP

High [CVE-2024-50403] QTS: use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.2.2.2952 build 20241116 and later

CVE-2024-50403
QTSQuTS hero
Dec 6, 2024
High7.2QNAP

High [CVE-2024-50402] QTS: use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.2.2.2952 build 20241116 and later

CVE-2024-50402
QTSQuTS hero
Dec 6, 2024
High7.5QNAP

High [CVE-2024-48868] QTS: improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating…

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.2.2.2952 build 20241116 and later

CVE-2024-48868
QTSQuTS hero
Dec 6, 2024
High7.5QNAP

High [CVE-2024-48865] QTS: improper certificate validation vulnerability has been reported to affect several QNAP operating system versions.

An improper certificate validation vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow attackers with local network access to compromise the security of the system. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.2.2.2952 build 20241116 and later

CVE-2024-48865
QTSQuTS hero
Dec 6, 2024
High7.2QNAP

High [CVE-2024-50401] QTS: use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

CVE-2024-50401
QTSQuTS hero
Nov 22, 2024
High8.8QNAP

High [CVE-2024-50397] QTS: use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

CVE-2024-50397
QTSQuTS hero
Nov 22, 2024
High8.8QNAP

High [CVE-2024-50396] QTS: use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

CVE-2024-50396
QTSQuTS hero
Nov 22, 2024
High8.8QNAP

High [CVE-2024-50395] authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on.

An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 2024/08/02 ) and later

CVE-2024-50395
Unclassified
Nov 22, 2024
High7.8QNAP

High [CVE-2024-48861] OS command injection vulnerability has been reported to affect several product versions.

An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands. We have already fixed the vulnerability in the following versions: QuRouter 2.4.4.106 and later

CVE-2024-48861
Unclassified
Nov 22, 2024
High7.5QNAP

High [CVE-2024-38647] exposure of sensitive information vulnerability has been reported to affect QNAP AI Core.

An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: QNAP AI Core 3.4.1 and later

CVE-2024-38647
Unclassified
Nov 22, 2024
High8.8QNAP

High [CVE-2024-38644] OS command injection vulnerability has been reported to affect Notes Station 3.

An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to execute commands. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later

CVE-2024-38644
Unclassified
Nov 22, 2024
High7.2QNAP

High [CVE-2024-37044] QTS: buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

CVE-2024-37044
QTSQuTS hero
Nov 22, 2024
High7.8QNAP

High [CVE-2024-38642] QuMagie: improper certificate validation vulnerability has been reported to affect QuMagie.

An improper certificate validation vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow local network users to compromise the security of the system via unspecified vectors. We have already fixed the vulnerability in the following version: QuMagie 2.3.1 and later

CVE-2024-38642
Applications
Sep 6, 2024
High7.8QNAP

High [CVE-2024-38641] QTS: OS command injection vulnerability has been reported to affect several QNAP operating system versions.

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local network users to execute commands via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later Affected products named by the advisory: QuTS hero.

CVE-2024-38641
QTSQuTS hero
Sep 6, 2024
High8.8QNAP

High [CVE-2024-32763] QTS: buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later Affected products named by the advisory: QuTS hero.

CVE-2024-32763
QTSQuTS hero
Sep 6, 2024
High8.2QNAP

High [CVE-2024-32762] cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center.

A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QuLog Center 1.8.0.872 ( 2024/06/17 ) and later

CVE-2024-32762
Unclassified
Sep 6, 2024
High8.8QNAP

High [CVE-2024-21898] QTS: OS command injection vulnerability has been reported to affect several QNAP operating system versions.

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 build 20240414 and later

CVE-2024-21898
QTSQuTS hero
Sep 6, 2024
High8.9QNAP

High [CVE-2024-21897] QTS: cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions.

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 build 20240414 and later

CVE-2024-21897
QTSQuTS hero
Sep 6, 2024
High8.7QNAP

High [CVE-2023-51366] QTS: path traversal vulnerability has been reported to affect several QNAP operating system versions.

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 build 20240414 and later

CVE-2023-51366
QTSQuTS hero
Sep 6, 2024