Vulnerabilities > Qnap

DATE CVE VULNERABILITY TITLE RISK
2024-02-02 CVE-2023-45037 Classic Buffer Overflow vulnerability in Qnap Qts, Quts Hero and Qutscloud
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions.
network
low complexity
qnap CWE-120
7.2
2024-02-02 CVE-2023-47561 Cross-site Scripting vulnerability in Qnap Photo Station 6.4.0
A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station.
network
low complexity
qnap CWE-79
5.4
2024-02-02 CVE-2023-47562 Command Injection vulnerability in Qnap Photo Station 6.4.0
An OS command injection vulnerability has been reported to affect Photo Station.
network
low complexity
qnap CWE-77
8.8
2024-02-02 CVE-2023-47564 Incorrect Permission Assignment for Critical Resource vulnerability in Qnap Qsync Central
An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central.
network
low complexity
qnap CWE-732
8.1
2024-02-02 CVE-2023-47566 OS Command Injection vulnerability in Qnap Qts, Quts Hero and Qutscloud
An OS command injection vulnerability has been reported to affect several QNAP operating system versions.
network
low complexity
qnap CWE-78
7.2
2024-02-02 CVE-2023-47567 OS Command Injection vulnerability in Qnap Qts, Quts Hero and Qutscloud
An OS command injection vulnerability has been reported to affect several QNAP operating system versions.
network
low complexity
qnap CWE-78
7.2
2024-02-02 CVE-2023-47568 SQL Injection vulnerability in Qnap Qts, Quts Hero and Qutscloud
A SQL injection vulnerability has been reported to affect several QNAP operating system versions.
network
low complexity
qnap CWE-89
8.8
2024-02-02 CVE-2023-50359 Unchecked Return Value vulnerability in Qnap Qts, Quts Hero and Qutscloud
An unchecked return value vulnerability has been reported to affect several QNAP operating system versions.
local
low complexity
qnap CWE-252
6.7
2024-01-05 CVE-2023-39294 OS Command Injection vulnerability in Qnap QTS and Quts Hero
An OS command injection vulnerability has been reported to affect several QNAP operating system versions.
network
low complexity
qnap CWE-78
7.2
2024-01-05 CVE-2023-39296 Unspecified vulnerability in Qnap QTS and Quts Hero
A prototype pollution vulnerability has been reported to affect several QNAP operating system versions.
network
low complexity
qnap
7.5