Vulnerabilities > Qbittorrent > Qbittorrent > 3.3.15

DATE CVE VULNERABILITY TITLE RISK
2023-10-10 CVE-2023-30801 Use of Hard-coded Credentials vulnerability in Qbittorrent
All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled.
network
low complexity
qbittorrent CWE-798
critical
9.8
2019-07-17 CVE-2019-13640 OS Command Injection vulnerability in Qbittorrent
In qBittorrent before 4.1.7, the function Application::runExternalProgram() located in app/application.cpp allows command injection via shell metacharacters in the torrent name parameter or current tracker parameter, as demonstrated by remote command execution via a crafted name within an RSS feed.
network
low complexity
qbittorrent CWE-78
critical
9.8
2019-05-09 CVE-2017-12778 Improper Authentication vulnerability in Qbittorrent 3.3.15
The UI Lock feature in qBittorrent version 3.3.15 is vulnerable to Authentication Bypass, which allows Attack to gain unauthorized access to qBittorrent functions by tampering the affected flag value of the config file at the C:\Users\<username>\Roaming\qBittorrent pathname.
local
low complexity
qbittorrent CWE-287
7.1