Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.8QNAP

High [CVE-2023-41288] Video Station: OS command injection vulnerability has been reported to affect Video Station.

An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.2 ( 2023/11/23 ) and later

CVE-2023-41288
Applications
Jan 5, 2024
High7.5QNAP

High [CVE-2023-39296] QTS: prototype pollution vulnerability has been reported to affect several QNAP operating system versions.

A prototype pollution vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to override existing attributes with ones that have incompatible type, which may lead to a crash via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later Affected products named by the advisory: QuTS hero.

CVE-2023-39296
QTSQuTS hero
Jan 5, 2024
High8.0QNAP Exploited CISA KEV

High [CVE-2023-47565] QVR: OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x.

An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QVR Firmware 5.0.0 and later

CVE-2023-47565
Surveillance (QVR)
Dec 8, 2023
High7.4QNAP

High [CVE-2023-41285] QuMagie: SQL injection vulnerability has been reported to affect QuMagie.

A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: QuMagie 2.1.4 and later

CVE-2023-41285
Applications
Nov 10, 2023
High8.8QNAP

High [CVE-2023-39295] QuMagie: OS command injection vulnerability has been reported to affect QuMagie.

An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: QuMagie 2.1.3 and later

CVE-2023-39295
Applications
Nov 10, 2023
Critical9.0QNAP

Critical [CVE-2023-23369] QTS: OS command injection vulnerability has been reported to affect several QNAP operating system versions.

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: Multimedia Console 2.1.2 ( 2023/05/04 ) and later QTS 5.1.0.2399 build 20230515 and later QTS 4.3.6.2441 build 20230621 and later Media Streaming add-on 500.1.1.2 ( 2023/06/12 ) and later

CVE-2023-23369
QTSApplications
Nov 3, 2023
Critical9.8QNAP

Critical [CVE-2023-23368] QTS: OS command injection vulnerability has been reported to affect several QNAP operating system versions.

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build 20230421 and later QTS 4.5.4.2374 build 20230416 and later QuTS hero h4.5.4.2374 build 20230417 and later Affected products named by the advisory: QuTScloud.

CVE-2023-23368
QTSQuTS hero
Nov 3, 2023
High7.5QNAP

High [CVE-2023-39299] Music Station: path traversal vulnerability has been reported to affect Music Station.

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: Music Station 4.8.11 and later

CVE-2023-39299
Applications
Nov 3, 2023
High8.8QNAP

High [CVE-2023-23373] OS command injection vulnerability has been reported to affect QUSBCam2.

An OS command injection vulnerability has been reported to affect QUSBCam2. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following version: QUSBCam2 2.0.3 ( 2023/06/15 ) and later

CVE-2023-23373
Unclassified
Oct 20, 2023
Critical10.0QNAP

Critical [CVE-2023-34976] Video Station: SQL injection vulnerability has been reported to affect Video Station.

A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.0 ( 2023/07/27 ) and later

CVE-2023-34976
Applications
Oct 13, 2023
High7.5QNAP

High [CVE-2023-32974] QTS: path traversal vulnerability has been reported to affect several QNAP operating system versions.

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.0.2444 build 20230629 and later QuTS hero h5.1.0.2424 build 20230609 and later QuTScloud c5.1.0.2498 and later

CVE-2023-32974
QTSQuTS hero
Oct 13, 2023
High7.7QNAP

High [CVE-2023-23366] Music Station: path traversal vulnerability has been reported to affect Music Station.

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following version: Music Station 5.3.22 and later

CVE-2023-23366
Applications
Oct 6, 2023
High8.1QNAP

High [CVE-2023-23364] Multimedia Console: buffer copy without checking size of input vulnerability has been reported to affect QNAP operating systems.

A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors. We have already fixed the vulnerability in the following versions: Multimedia Console 2.1.1 ( 2023/03/29 ) and later

CVE-2023-23364
Applications
Sep 22, 2023
High8.1QNAP

High [CVE-2023-23363] QTS: buffer copy without checking size of input vulnerability has been reported to affect QNAP operating system.

A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating system. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 4.3.6.2441 build 20230621 and later

CVE-2023-23363
QTS
Sep 22, 2023
High8.8QNAP

High [CVE-2023-23362] QTS: OS command injection vulnerability has been reported to affect QNAP operating systems.

An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability allows remote authenticated users to execute commands via susceptible QNAP devices. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build 20230421 and later QTS 4.5.4.2374 build 20230416 and later QuTS hero h4.5.4.2374 build 20230417 and later Affected products named by the advisory: QuTScloud.

CVE-2023-23362
QTSQuTS hero
Sep 22, 2023
High7.1QNAP

High [CVE-2023-34971] QTS: inadequate encryption strength vulnerability has been reported to affect QNAP operating systems.

An inadequate encryption strength vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows local network clients to decrypt the data using brute force attacks via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5.1.0.2444 build 20230629 and later QTS 4.5.4.2467 build 20230718 and later QuTS hero h5.1.0.2424 build 20230609 and later QuTS hero h4.5.4.2476 build 20230728 and later

CVE-2023-34971
QTSQuTS hero
Aug 24, 2023
Critical9.8QNAP

Critical [CVE-2022-27596] QTS: vulnerability has been reported to affect QNAP device running QuTS hero, QTS.

A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QuTS hero, QTS: QuTS hero h5.0.1.2248 build 20221215 and later QTS 5.0.1.2234 build 20221201 and later

CVE-2022-27596
QTSQuTS hero
Jan 30, 2023
Critical10.0QNAP Exploited CISA KEV

Critical [CVE-2022-27593] QTS: externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later

CVE-2022-27593
QTSApplications
Sep 8, 2022
Critical9.8QNAP

Critical [CVE-2022-27588] QVR: We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.6 build 20220401 and later

We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.6 build 20220401 and later

CVE-2022-27588
Surveillance (QVR)
May 5, 2022
High7.1QNAP

High [CVE-2021-44057] Photo Station: improper authentication vulnerability has been reported to affect QNAP device running Photo Station.

An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.20 ( 2022/02/15 ) and later Photo Station 5.7.16 ( 2022/02/11 ) and later Photo Station 5.4.13 ( 2022/02/11 ) and later

CVE-2021-44057
Applications
May 5, 2022