Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.6QNAP

High [CVE-2025-59382 +16] QuTS hero: cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions.

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.3499 build 20260514 and later QuTS hero h5.3.4.3500 build 20260520 and later Affected products named by the advisory: QuTScloud. Affected products named by the advisory: QVP 2.7.1; QuTS cloud c5.2.8; QTS version 5.2.7; QuTS hero h5.2.8.

CVE-2025-59382CVE-2025-62858CVE-2025-66273+14
QTSQuTS hero
Jun 9, 2026
High8.7QNAP

High [CVE-2025-62851 +3] QuMagie: missing authorization vulnerability has been reported to affect QuMagie.

A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the following version: QuMagie 2.9.0 and later Affected products named by the advisory: License Center. Affected products named by the advisory: QuMagie 2.8.2; License Center 1.8.56.

CVE-2025-62851CVE-2026-26236CVE-2026-26237+1
Applications
Jun 9, 2026
High8.1QNAP

High [CVE-2026-22897 +3] command injection vulnerability has been reported to affect QuNetSwitch.

A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.4.0415 and later Affected product named by the advisory: QuNetSwitch 2.0.x.

CVE-2026-22897CVE-2026-22900CVE-2026-22901+1
Unclassified
Mar 20, 2026
High7.3QNAP

High [CVE-2025-62843 +3] improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora.

An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. If an attacker gains physical access, they can then exploit the vulnerability to gain the privileges that were intended for the original endpoint. We have already fixed the vulnerability in the following version: QuRouter 2.6.3.009 and later Affected product named by the advisory: QuRouter 2.6.x.

CVE-2025-62843CVE-2025-62844CVE-2025-62845+1
Unclassified
Mar 20, 2026