Vulnerabilities > Qnap

DATE CVE VULNERABILITY TITLE RISK
2021-06-11 CVE-2021-28805 Information Exposure vulnerability in Qnap QSS 1.0.2/1.0.3
Inclusion of sensitive information in the source code has been reported to affect certain QNAP switches running QSS.
local
low complexity
qnap CWE-200
5.5
2021-06-11 CVE-2021-28814 Unspecified vulnerability in Qnap Helpdesk
An improper access control vulnerability has been reported to affect QNAP NAS.
network
low complexity
qnap
8.8
2021-06-08 CVE-2021-28810 Authentication Bypass by Spoofing vulnerability in Qnap Roon Server
If exploited, this vulnerability allows an attacker to access resources which are not otherwise accessible without proper authentication.
network
low complexity
qnap CWE-290
5.0
2021-06-03 CVE-2021-28806 Cross-site Scripting vulnerability in Qnap QTS
A DOM-based XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero.
network
qnap CWE-79
3.5
2021-06-03 CVE-2021-28807 Cross-site Scripting vulnerability in Qnap Q'Center
A post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’center.
network
qnap CWE-79
3.5
2021-06-03 CVE-2021-28812 Command Injection vulnerability in Qnap Video Station
A command injection vulnerability has been reported to affect certain versions of Video Station.
network
low complexity
qnap CWE-77
8.8
2021-05-21 CVE-2021-28798 Path Traversal vulnerability in Qnap QTS and Quts Hero
A relative path traversal vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero.
network
low complexity
qnap CWE-22
7.5
2021-05-13 CVE-2020-36197 Improper Access Control vulnerability in Qnap Music Station
An improper access control vulnerability has been reported to affect earlier versions of Music Station.
low complexity
qnap CWE-284
5.8
2021-05-13 CVE-2020-36198 OS Command Injection vulnerability in Qnap Malware Remover
A command injection vulnerability has been reported to affect certain versions of Malware Remover.
local
low complexity
qnap CWE-78
7.2
2021-05-13 CVE-2021-28799 Unspecified vulnerability in Qnap Hybrid Backup Sync
An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync.
network
low complexity
qnap
critical
9.8