Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.8QNAP

High [CVE-2024-13088] improper authentication vulnerability has been reported to affect QHora.

An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: QuRouter 2.5.0.140 and later

CVE-2024-13088
Unclassified
Jun 6, 2025
Critical9.1QNAP

Critical [CVE-2024-53695] HBS: buffer overflow vulnerability has been reported to affect HBS 3 Hybrid Backup Sync.

A buffer overflow vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to modify memory or crash processes. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.4.952 and later

CVE-2024-53695
Backup (HBS)
Mar 7, 2025
Critical9.8QNAP

Critical [CVE-2024-50390] command injection vulnerability has been reported to affect QHora.

A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later

CVE-2024-50390
Unclassified
Mar 7, 2025
Critical9.1QNAP

Critical [CVE-2024-48864] files or directories accessible to external parties vulnerability has been reported to affect File Station 5.

A files or directories accessible to external parties vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers to read/write files or directories. We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4741 and later

CVE-2024-48864
Unclassified
Mar 7, 2025
High7.2QNAP

High [CVE-2024-53700] command injection vulnerability has been reported to affect QHora.

A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.6.028 and later

CVE-2024-53700
Unclassified
Mar 7, 2025
High7.2QNAP

High [CVE-2024-53699] QTS: out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions.

An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later Affected products named by the advisory: QuTS hero.

CVE-2024-53699
QTSQuTS hero
Mar 7, 2025
High7.1QNAP

High [CVE-2024-53693] QTS: improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating…

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to modify application data. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later Affected products named by the advisory: QuTS hero.

CVE-2024-53693
QTSQuTS hero
Mar 7, 2025
High8.8QNAP

High [CVE-2024-50394] Helpdesk: improper certificate validation vulnerability has been reported to affect Helpdesk.

An improper certificate validation vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: Helpdesk 3.3.3 and later

CVE-2024-50394
Unclassified
Mar 7, 2025
High7.2QNAP

High [CVE-2024-38638] QTS: out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions.

An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. QTS 5.2.x/QuTS hero h5.2.x are not affected. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later

CVE-2024-38638
QTSQuTS hero
Mar 7, 2025
High7.3QNAP

High [CVE-2023-23354] cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions.

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QuLog Center 1.5.0.738 ( 2023/03/06 ) and later

CVE-2023-23354
Unclassified
Dec 19, 2024
High7.8QNAP

High [CVE-2022-27595] insecure library loading vulnerability has been reported to affect QVPN Device Client.

An insecure library loading vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local attackers who have gained user access to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: QVPN Windows 2.0.0.1316 and later

CVE-2022-27595
Unclassified
Dec 19, 2024
Critical9.8QNAP

Critical [CVE-2024-50393] QTS: command injection vulnerability has been reported to affect several QNAP operating system versions.

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.2.2.2952 build 20241116 and later

CVE-2024-50393
QTSQuTS hero
Dec 6, 2024
Critical9.8QNAP

Critical [CVE-2024-50389] SQL injection vulnerability has been reported to affect QuRouter.

A SQL injection vulnerability has been reported to affect QuRouter. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later

CVE-2024-50389
Unclassified
Dec 6, 2024
Critical9.8QNAP

Critical [CVE-2024-50388] HBS: OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync.

An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.1.673 and later

CVE-2024-50388
Backup (HBS)
Dec 6, 2024
Critical9.8QNAP

Critical [CVE-2024-50387] SQL injection vulnerability has been reported to affect several QNAP operating system versions.

A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: SMB Service 4.15.002 and later

CVE-2024-50387
Unclassified
Dec 6, 2024
Critical9.8QNAP

Critical [CVE-2024-48863] License Center: command injection vulnerability has been reported to affect License Center.

A command injection vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following version: License Center 1.9.43 and later

CVE-2024-48863
Unclassified
Dec 6, 2024
Critical9.1QNAP

Critical [CVE-2024-48859] QTS: improper authentication vulnerability has been reported to affect several QNAP operating system versions.

An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.2.2.2952 build 20241116 and later

CVE-2024-48859
QTSQuTS hero
Dec 6, 2024
High8.8QNAP

High [CVE-2024-53691] QTS: link following vulnerability has been reported to affect several QNAP operating system versions.

A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QTS 5.2.0.2802 build 20240620 and later Affected products named by the advisory: QuTS hero.

CVE-2024-53691
QTSQuTS hero
Dec 6, 2024
High8.8QNAP

High [CVE-2024-50404] Qsync: link following vulnerability has been reported to affect Qsync Central.

A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.16_20240819 ( 2024/08/19 ) and later

CVE-2024-50404
Applications
Dec 6, 2024
High7.2QNAP

High [CVE-2024-50403] QTS: use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.2.2.2952 build 20241116 and later

CVE-2024-50403
QTSQuTS hero
Dec 6, 2024