Vulnerabilities > Qnap

DATE CVE VULNERABILITY TITLE RISK
2024-01-05 CVE-2023-47559 Cross-site Scripting vulnerability in Qnap Qumagie 2.2.0
A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie.
network
low complexity
qnap CWE-79
5.4
2024-01-05 CVE-2023-47560 Command Injection vulnerability in Qnap Qumagie 2.2.0
An OS command injection vulnerability has been reported to affect QuMagie.
network
low complexity
qnap CWE-77
8.8
2023-12-08 CVE-2023-23372 Cross-site Scripting vulnerability in Qnap QTS and Quts Hero
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions.
network
low complexity
qnap CWE-79
6.1
2023-12-08 CVE-2023-32968 Classic Buffer Overflow vulnerability in Qnap QTS and Quts Hero
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions.
network
low complexity
qnap CWE-120
7.2
2023-12-08 CVE-2023-32975 Classic Buffer Overflow vulnerability in Qnap QTS and Quts Hero
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions.
network
low complexity
qnap CWE-120
7.2
2023-12-08 CVE-2023-47565 OS Command Injection vulnerability in Qnap QVR Firmware
An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x.
network
low complexity
qnap CWE-78
8.8
2023-11-10 CVE-2023-39295 OS Command Injection vulnerability in Qnap Qumagie
An OS command injection vulnerability has been reported to affect QuMagie.
network
low complexity
qnap CWE-78
8.8
2023-11-10 CVE-2023-41284 SQL Injection vulnerability in Qnap Qumagie
A SQL injection vulnerability has been reported to affect QuMagie.
network
low complexity
qnap CWE-89
8.8
2023-11-10 CVE-2023-41285 SQL Injection vulnerability in Qnap Qumagie
A SQL injection vulnerability has been reported to affect QuMagie.
network
low complexity
qnap CWE-89
8.8
2023-11-10 CVE-2023-23367 OS Command Injection vulnerability in Qnap Qts, Quts Hero and Qutscloud
An OS command injection vulnerability has been reported to affect several QNAP operating system versions.
network
low complexity
qnap CWE-78
7.2