Vulnerabilities > Qnap > QTS > 4.3.3.1945

DATE CVE VULNERABILITY TITLE RISK
2022-05-05 CVE-2021-38693 Path Traversal vulnerability in Qnap QTS and Qutscloud
A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Appliance.
network
low complexity
qnap CWE-22
5.3
2022-01-07 CVE-2021-38674 Cross-site Scripting vulnerability in Qnap QTS and Quts Hero
A cross-site scripting (XSS) vulnerability has been reported to affect QTS, QuTS hero and QuTScloud.
network
low complexity
qnap CWE-79
6.1
2021-09-10 CVE-2018-19957 Improper Restriction of Rendered UI Layers or Frames vulnerability in Qnap Qts, Quts Hero and Qutscloud
A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS running QTS, QuTS hero, and QuTScloud.
network
low complexity
qnap CWE-1021
6.1
2021-07-01 CVE-2020-36194 Cross-site Scripting vulnerability in Qnap QTS and Quts Hero
An XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero.
network
low complexity
qnap CWE-79
6.1
2021-07-01 CVE-2021-28802 Unspecified vulnerability in Qnap QTS and Quts Hero
A command injection vulnerabilities have been reported to affect QTS and QuTS hero.
network
low complexity
qnap
critical
9.8
2021-07-01 CVE-2021-28804 Unspecified vulnerability in Qnap QTS and Quts Hero
A command injection vulnerabilities have been reported to affect QTS and QuTS hero.
network
low complexity
qnap
critical
9.8
2021-06-03 CVE-2021-28806 Unspecified vulnerability in Qnap QTS
A DOM-based XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero.
network
low complexity
qnap
5.4
2021-01-11 CVE-2020-2508 Command Injection vulnerability in Qnap QTS
A command injection vulnerability has been reported to affect QTS and QuTS hero.
network
low complexity
qnap CWE-77
7.2
2020-12-31 CVE-2018-19944 Cleartext Transmission of Sensitive Information vulnerability in Qnap QTS
A cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices.
network
low complexity
qnap CWE-319
7.5
2020-12-31 CVE-2018-19941 Cleartext Storage of Sensitive Information vulnerability in Qnap QTS
A vulnerability has been reported to affect QNAP NAS.
network
low complexity
qnap CWE-312
7.5