Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.8QNAP

Critical [CVE-2017-20210] Photo Station 5.4.1 & 5.2.7 include the security fix for the vulnerability related to the XMR mining programs identified by…

Photo Station 5.4.1 & 5.2.7 include the security fix for the vulnerability related to the XMR mining programs identified by internal research. Affected products named by the advisory: QTS.

CVE-2017-20210
QTSApplications
Nov 11, 2025
Critical9.8QNAP

Critical [CVE-2025-52856] improper authentication vulnerability has been reported to affect VioStor.

An improper authentication vulnerability has been reported to affect VioStor. If a remote attacker, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: VioStor 5.1.6 build 20250621 and later

CVE-2025-52856
Unclassified
Aug 29, 2025
Critical9.1QNAP

Critical [CVE-2024-53695] HBS: buffer overflow vulnerability has been reported to affect HBS 3 Hybrid Backup Sync.

A buffer overflow vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to modify memory or crash processes. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.4.952 and later

CVE-2024-53695
Backup (HBS)
Mar 7, 2025
Critical9.8QNAP

Critical [CVE-2024-50390] command injection vulnerability has been reported to affect QHora.

A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later

CVE-2024-50390
Unclassified
Mar 7, 2025
Critical9.1QNAP

Critical [CVE-2024-48864] files or directories accessible to external parties vulnerability has been reported to affect File Station 5.

A files or directories accessible to external parties vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers to read/write files or directories. We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4741 and later

CVE-2024-48864
Unclassified
Mar 7, 2025
Critical9.8QNAP

Critical [CVE-2024-50393] QTS: command injection vulnerability has been reported to affect several QNAP operating system versions.

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.2.2.2952 build 20241116 and later

CVE-2024-50393
QTSQuTS hero
Dec 6, 2024
Critical9.8QNAP

Critical [CVE-2024-50389] SQL injection vulnerability has been reported to affect QuRouter.

A SQL injection vulnerability has been reported to affect QuRouter. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later

CVE-2024-50389
Unclassified
Dec 6, 2024
Critical9.8QNAP

Critical [CVE-2024-50388] HBS: OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync.

An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.1.673 and later

CVE-2024-50388
Backup (HBS)
Dec 6, 2024
Critical9.8QNAP

Critical [CVE-2024-50387] SQL injection vulnerability has been reported to affect several QNAP operating system versions.

A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: SMB Service 4.15.002 and later

CVE-2024-50387
Unclassified
Dec 6, 2024
Critical9.8QNAP

Critical [CVE-2024-48863] License Center: command injection vulnerability has been reported to affect License Center.

A command injection vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following version: License Center 1.9.43 and later

CVE-2024-48863
Unclassified
Dec 6, 2024
Critical9.1QNAP

Critical [CVE-2024-48859] QTS: improper authentication vulnerability has been reported to affect several QNAP operating system versions.

An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.2.2.2952 build 20241116 and later

CVE-2024-48859
QTSQuTS hero
Dec 6, 2024
Critical9.8QNAP

Critical [CVE-2024-48862] link following vulnerability has been reported to affect QuLog Center.

A link following vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. We have already fixed the vulnerability in the following versions: QuLog Center 1.7.0.831 ( 2024/10/15 ) and later

CVE-2024-48862
Unclassified
Nov 22, 2024
Critical9.8QNAP

Critical [CVE-2024-48860] OS command injection vulnerability has been reported to affect several product versions.

An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.3.103 and later

CVE-2024-48860
Unclassified
Nov 22, 2024
Critical9.8QNAP

Critical [CVE-2024-38643] missing authentication for critical function vulnerability has been reported to affect Notes Station 3.

A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote attackers to gain access to and execute certain functions. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later

CVE-2024-38643
Unclassified
Nov 22, 2024
Critical10.0QNAP

Critical [CVE-2024-32766] QTS: OS command injection vulnerability has been reported to affect several QNAP operating system versions.

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later

CVE-2024-32766
QTSQuTS hero
Apr 26, 2024
Critical9.9QNAP

Critical [CVE-2024-32764] myQNAPcloud: missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link.

A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited, the vulnerability could allow users with the privilege level of some functionality via a network. We have already fixed the vulnerability in the following version: myQNAPcloud Link 2.4.51 and later

CVE-2024-32764
Unclassified
Apr 26, 2024
Critical9.6QNAP

Critical [CVE-2023-47222] exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on.

An exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.5 ( 2024/01/22 ) and later

CVE-2023-47222
Unclassified
Apr 26, 2024
Critical9.8QNAP

Critical [CVE-2024-21899] QTS: improper authentication vulnerability has been reported to affect several QNAP operating system versions.

An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later

CVE-2024-21899
QTSQuTS hero
Mar 8, 2024
Critical9.0QNAP

Critical [CVE-2023-45025] QTS: OS command injection vulnerability has been reported to affect several QNAP operating system versions.

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later

CVE-2023-45025
QTSQuTS hero
Feb 2, 2024
Critical9.0QNAP

Critical [CVE-2023-23369] QTS: OS command injection vulnerability has been reported to affect several QNAP operating system versions.

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: Multimedia Console 2.1.2 ( 2023/05/04 ) and later QTS 5.1.0.2399 build 20230515 and later QTS 4.3.6.2441 build 20230621 and later Media Streaming add-on 500.1.1.2 ( 2023/06/12 ) and later

CVE-2023-23369
QTSApplications
Nov 3, 2023