Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.1QNAP

High [CVE-2021-44056] Video Station: improper authentication vulnerability has been reported to affect QNAP device running Video Station.

An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Video Station: Video Station 5.5.9 and later Video Station 5.3.13 and later Video Station 5.1.8 and later

CVE-2021-44056
Applications
May 5, 2022
High8.8QNAP

High [CVE-2021-44051] QTS: command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS.

A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero and QTS: QuTScloud c5.0.1.1949 and later QuTS hero h5.0.0.1986 build 20220324 and later QTS 5.0.0.1986 build 20220324 and later

CVE-2021-44051
QTSQuTS hero
May 5, 2022
High8.1QNAP

High [CVE-2021-38692] QTS: stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard.

A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QVR Elite, QVR Pro, QVR Guard: QuTS hero h5.0.0: QVR Elite 2.1.4.0 (2021/12/06) and later QuTS hero h4.5.4: QVR Elite 2.1.4.0 (2021/12/06) and later QTS 5.0.0: QVR Elite 2.1.4.0 (2021/12/06) and later QTS 4.5.4: QVR Elite 2.1.4.0 (2021/12/06) and later QTS 4.5.4: QVR Pro 2.1.3.0 (2021/12/06) and later QTS 5.0.0: QVR Pro 2.1.3.0 (2021/12/06) and later QTS 4.5.4: QVR Guard 2.1.3.0 (2021/12/06) and later QTS 5.0.0: QVR Guard 2.1.3.0 (2021/12/06) and later

CVE-2021-38692
QTSQuTS heroSurveillance (QVR)
Jan 14, 2022
High8.1QNAP

High [CVE-2021-38682] QTS: stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard.

A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QVR Elite, QVR Pro, QVR Guard: QuTS hero h5.0.0: QVR Elite 2.1.4.0 (2021/12/06) and later QuTS hero h4.5.4: QVR Elite 2.1.4.0 (2021/12/06) and later QTS 5.0.0: QVR Elite 2.1.4.0 (2021/12/06) and later QTS 4.5.4: QVR Elite 2.1.4.0 (2021/12/06) and later QTS 4.5.4: QVR Pro 2.1.3.0 (2021/12/06) and later QTS 5.0.0: QVR Pro 2.1.3.0 (2021/12/06) and later QTS 4.5.4: QVR Guard 2.1.3.0 and later QTS 5.0.0: QVR Guard 2.1.3.0 and later

CVE-2021-38682
QTSQuTS heroSurveillance (QVR)
Jan 14, 2022
High7.1QNAP

High [CVE-2021-38688] improper authentication vulnerability has been reported to affect Android App Qfile.

An improper authentication vulnerability has been reported to affect Android App Qfile. If exploited, this vulnerability allows attackers to compromise app and access information We have already fixed this vulnerability in the following versions of Qfile: Qfile 3.0.0.1105 and later

CVE-2021-38688
Unclassified
Dec 29, 2021
High8.1QNAP

High [CVE-2021-38687] QTS: stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station.

A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of Surveillance Station: QTS 5.0.0 (64 bit): Surveillance Station 5.2.0.4.2 ( 2021/10/26 ) and later QTS 5.0.0 (32 bit): Surveillance Station 5.2.0.3.2 ( 2021/10/26 ) and later QTS 4.3.6 (64 bit): Surveillance Station 5.1.5.4.6 ( 2021/10/26 ) and later QTS 4.3.6 (32 bit): Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later QTS 4.3.3: Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later

CVE-2021-38687
QTS
Dec 29, 2021
Critical9.8QNAP

Critical [CVE-2020-2501] QNAP NAS: stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station.

A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. QNAP have already fixed this vulnerability in the following versions: Surveillance Station 5.1.5.4.3 (and later) for ARM CPU NAS (64bit OS) and x86 CPU NAS (64bit OS) Surveillance Station 5.1.5.3.3 (and later) for ARM CPU NAS (32bit OS) and x86 CPU NAS (32bit OS)

CVE-2020-2501
Unclassified
Feb 17, 2021
Critical9.8QNAP

Critical [CVE-2020-2507] QTS: The vulnerability have been reported to affect earlier versions of QTS.

The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.

CVE-2020-2507
QTS
Feb 3, 2021
High7.3QNAP Exploited CISA KEV

High [CVE-2020-2506] QTS: The vulnerability have been reported to affect earlier versions of QTS.

The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.

CVE-2020-2506
QTS
Feb 3, 2021
High7.2QNAP

High [CVE-2020-2508] QTS: command injection vulnerability has been reported to affect QTS and QuTS hero.

A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and later) QuTS hero h4.5.1.1472 build 20201031 (and later)

CVE-2020-2508
QTSQuTS hero
Jan 11, 2021
Critical9.1QNAP

Critical [CVE-2018-19945] QTS: vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6.

A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitations of a pathname to a restricted directory, this vulnerability allows for renaming arbitrary files on the target system, if exploited. QNAP have already fixed this vulnerability in the following versions: QTS 4.3.6.0895 build 20190328 (and later) QTS 4.3.4.0899 build 20190322 (and later) This issue does not affect QTS 4.4.x or QTS 4.5.x.

CVE-2018-19945
QTS
Dec 31, 2020
High7.5QNAP

High [CVE-2018-19944] QTS: cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices.

A cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices. If exploited, this vulnerability allows a remote attacker to gain access to sensitive information. QNAP have already fixed this vulnerability in the following versions: QTS 4.4.3.1354 build 20200702 (and later)

CVE-2018-19944
QTS
Dec 31, 2020
High7.5QNAP

High [CVE-2018-19941] QTS: vulnerability has been reported to affect QNAP NAS.

A vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows an attacker to access sensitive information stored in cleartext inside cookies via certain widely-available tools. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and later) QuTS hero h4.5.1.1472 build 20201031 (and later) QuTScloud c4.5.2.1379 build 20200730 (and later)

CVE-2018-19941
QTSQuTS hero
Dec 31, 2020
Critical9.0QNAP

Critical [CVE-2020-2503] If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station

If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

CVE-2020-2503
Unclassified
Dec 24, 2020
Critical9.8QNAP

Critical [CVE-2019-7198] QTS: This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application.

This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later

CVE-2019-7198
QTSQuTS hero
Dec 10, 2020
High7.2QNAP

High [CVE-2020-2492] QTS: If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands.

If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.

CVE-2020-2492
QTS
Nov 16, 2020
Critical9.8QNAP

Critical [CVE-2018-19950] Music Station: If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands.

If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.

CVE-2018-19950
Applications
Nov 2, 2020
High7.5QNAP

High [CVE-2018-19952] Music Station: If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information.

If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.

CVE-2018-19952
Applications
Nov 2, 2020
Critical9.8QNAP Exploited CISA KEV

Critical [CVE-2018-19949] QTS: If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands.

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

CVE-2018-19949
QTS
Oct 28, 2020
High8.0QNAP Exploited CISA KEV

High [CVE-2018-19943] QTS: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later

CVE-2018-19943
QTS
Oct 28, 2020