Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.8QNAP

High [CVE-2025-44014] Qsync: out-of-bounds write vulnerability has been reported to affect Qsync Central.

An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.1 ( 2025/07/09 ) and later

CVE-2025-44014
Applications
Oct 3, 2025
High8.8QNAP

High [CVE-2024-56804] Video Station: SQL injection vulnerability has been reported to affect Video Station.

An SQL injection vulnerability has been reported to affect Video Station. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Video Station 5.8.4 and later

CVE-2024-56804
Applications
Oct 3, 2025
High8.4QNAP

High [CVE-2025-44015] command injection vulnerability has been reported to affect HybridDesk Station.

A command injection vulnerability has been reported to affect HybridDesk Station. If an attacker gains local network access, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: HybridDesk Station 4.2.18 and later

CVE-2025-44015
Unclassified
Aug 29, 2025
High8.8QNAP

High [CVE-2025-30278] Qsync: improper certificate validation vulnerability has been reported to affect Qsync Central.

An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later

CVE-2025-30278
Applications
Aug 29, 2025
High8.1QNAP

High [CVE-2025-30273] QTS: out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions.

An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later

CVE-2025-30273
QTSQuTS hero
Aug 29, 2025
High8.8QNAP

High [CVE-2025-30264] QTS: command injection vulnerability has been reported to affect several QNAP operating system versions.

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later

CVE-2025-30264
QTSQuTS hero
Aug 29, 2025
High8.8QNAP

High [CVE-2025-29894] Qsync: SQL injection vulnerability has been reported to affect Qsync Central.

An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later

CVE-2025-29894
Applications
Aug 29, 2025
High7.2QNAP

High [CVE-2025-29887] command injection vulnerability has been reported to affect QuRouter 2.5.1.

A command injection vulnerability has been reported to affect QuRouter 2.5.1. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.5.1.060 and later

CVE-2025-29887
Unclassified
Aug 29, 2025
High8.1QNAP

High [CVE-2025-47206] out-of-bounds write vulnerability has been reported to affect File Station 5.

An out-of-bounds write vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4933 and later

CVE-2025-47206
Unclassified
Aug 18, 2025
High8.8QNAP

High [CVE-2025-33031] improper certificate validation vulnerability has been reported to affect File Station 5.

An improper certificate validation vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later

CVE-2025-33031
Unclassified
Jun 6, 2025
High8.8QNAP

High [CVE-2025-29892] Qsync: SQL injection vulnerability has been reported to affect Qsync Central.

An SQL injection vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.6 ( 2025/03/20 ) and later

CVE-2025-29892
Applications
Jun 6, 2025
High8.8QNAP

High [CVE-2025-29885] improper certificate validation vulnerability has been reported to affect File Station 5.

An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user access to compromise the security of the system. We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4791 and later

CVE-2025-29885
Unclassified
Jun 6, 2025
High7.5QNAP

High [CVE-2025-29877] NULL pointer dereference vulnerability has been reported to affect File Station 5.

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later

CVE-2025-29877
Unclassified
Jun 6, 2025
High7.5QNAP

High [CVE-2025-29872] allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5.

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later

CVE-2025-29872
Unclassified
Jun 6, 2025
High8.1QNAP

High [CVE-2025-22482] Qsync: use of externally-controlled format string vulnerability has been reported to affect Qsync Central.

A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to obtain secret data or modify memory. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.6 ( 2025/03/20 ) and later

CVE-2025-22482
Applications
Jun 6, 2025
High8.8QNAP

High [CVE-2025-22481] QTS: command injection vulnerability has been reported to affect several QNAP operating system versions.

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.4.3079 build 20250321 and later Affected products named by the advisory: QuTS hero.

CVE-2025-22481
QTSQuTS hero
Jun 6, 2025
High7.8QNAP

High [CVE-2024-13088] improper authentication vulnerability has been reported to affect QHora.

An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: QuRouter 2.5.0.140 and later

CVE-2024-13088
Unclassified
Jun 6, 2025
High7.2QNAP

High [CVE-2024-53700] command injection vulnerability has been reported to affect QHora.

A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.6.028 and later

CVE-2024-53700
Unclassified
Mar 7, 2025
High7.2QNAP

High [CVE-2024-53699] QTS: out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions.

An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later Affected products named by the advisory: QuTS hero.

CVE-2024-53699
QTSQuTS hero
Mar 7, 2025
High7.1QNAP

High [CVE-2024-53693] QTS: improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating…

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to modify application data. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later Affected products named by the advisory: QuTS hero.

CVE-2024-53693
QTSQuTS hero
Mar 7, 2025