Complete feed
Security advisories & CVEs
46 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Critical [CVE-2025-66276] QuTS hero: QuTS hero is not affected.
QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later Affected product named by the advisory: QTS 4.3.x.
Critical [CVE-2026-22898] QVR Pro: missing authentication for critical function vulnerability has been reported to affect QVR Pro.
A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerability to gain access to the system. We have already fixed the vulnerability in the following version: QVR Pro 2.7.4.14 and later Affected product named by the advisory: QVR Pro 2.7.x.
Critical [CVE-2025-59389] SQL injection vulnerability has been reported to affect Hyper Data Protector.
An SQL injection vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: Hyper Data Protector 2.2.4.1 and later Affected product named by the advisory: Hyper Data Protector 2.2.x.
Critical [CVE-2025-11837] Malware Remover: improper control of generation of code vulnerability has been reported to affect Malware Remover.
An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attackers can then exploit the vulnerability to bypass protection mechanism. We have already fixed the vulnerability in the following version: Malware Remover 6.6.8.20251023 and later Affected product named by the advisory: Malware Remover 6.6.x.
Critical [CVE-2025-62849] QTS: SQL injection vulnerability has been reported to affect several QNAP operating system versions.
An SQL injection vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later Affected products named by the advisory: QTS 5.2.x; QuTS hero h5.2.x; QuTS hero h5.3.x.
Critical [CVE-2025-59385] QTS: authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions.
An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to access resources which are not otherwise accessible without proper authentication. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later Affected products named by the advisory: QTS 5.2.x; QuTS hero h5.2.x; QuTS hero h5.3.x.
Critical [CVE-2017-20210] Photo Station 5.4.1 & 5.2.7 include the security fix for the vulnerability related to the XMR mining programs identified by…
Photo Station 5.4.1 & 5.2.7 include the security fix for the vulnerability related to the XMR mining programs identified by internal research. Affected products named by the advisory: QTS.
Critical [CVE-2025-52425] QuMagie: SQL injection vulnerability has been reported to affect QuMagie.
An SQL injection vulnerability has been reported to affect QuMagie. A remote attacker can exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: QuMagie 2.7.0 and later Affected product named by the advisory: QuMagie 2.6.x.
Critical [CVE-2025-52856] improper authentication vulnerability has been reported to affect VioStor.
An improper authentication vulnerability has been reported to affect VioStor. If a remote attacker, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: VioStor 5.1.6 build 20250621 and later
Critical [CVE-2024-53695] HBS: buffer overflow vulnerability has been reported to affect HBS 3 Hybrid Backup Sync.
A buffer overflow vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to modify memory or crash processes. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.4.952 and later
Critical [CVE-2024-50390] command injection vulnerability has been reported to affect QHora.
A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later
Critical [CVE-2024-48864] files or directories accessible to external parties vulnerability has been reported to affect File Station 5.
A files or directories accessible to external parties vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers to read/write files or directories. We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4741 and later
Critical [CVE-2024-50393] QTS: command injection vulnerability has been reported to affect several QNAP operating system versions.
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.2.2.2952 build 20241116 and later
Critical [CVE-2024-50389] SQL injection vulnerability has been reported to affect QuRouter.
A SQL injection vulnerability has been reported to affect QuRouter. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later
Critical [CVE-2024-50388] HBS: OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync.
An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.1.673 and later
Critical [CVE-2024-50387] SQL injection vulnerability has been reported to affect several QNAP operating system versions.
A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: SMB Service 4.15.002 and later
Critical [CVE-2024-48863] License Center: command injection vulnerability has been reported to affect License Center.
A command injection vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following version: License Center 1.9.43 and later
Critical [CVE-2024-48859] QTS: improper authentication vulnerability has been reported to affect several QNAP operating system versions.
An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.2.2.2952 build 20241116 and later
Critical [CVE-2024-48862] link following vulnerability has been reported to affect QuLog Center.
A link following vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. We have already fixed the vulnerability in the following versions: QuLog Center 1.7.0.831 ( 2024/10/15 ) and later
Critical [CVE-2024-48860] OS command injection vulnerability has been reported to affect several product versions.
An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.3.103 and later