Vulnerabilities > Qnap > QTS > 4.5.4.2374

DATE CVE VULNERABILITY TITLE RISK
2023-12-08 CVE-2023-23372 Cross-site Scripting vulnerability in Qnap QTS and Quts Hero
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions.
network
low complexity
qnap CWE-79
6.1
2023-11-03 CVE-2023-39301 Unspecified vulnerability in Qnap QTS
A server-side request forgery (SSRF) vulnerability has been reported to affect several QNAP operating system versions.
network
low complexity
qnap
4.3
2023-10-13 CVE-2023-32970 NULL Pointer Dereference vulnerability in Qnap QTS and Quts Hero
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions.
network
low complexity
qnap CWE-476
4.9
2023-10-13 CVE-2023-32973 Out-of-bounds Write vulnerability in Qnap QTS and Quts Hero
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions.
network
low complexity
qnap CWE-787
7.2
2023-10-06 CVE-2023-32971 Out-of-bounds Write vulnerability in Qnap QTS and Quts Hero
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions.
network
low complexity
qnap CWE-787
7.2
2023-10-06 CVE-2023-32972 Out-of-bounds Write vulnerability in Qnap QTS and Quts Hero
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions.
network
low complexity
qnap CWE-787
7.2
2023-08-24 CVE-2023-34971 Inadequate Encryption Strength vulnerability in Qnap QTS and Quts Hero
An inadequate encryption strength vulnerability has been reported to affect QNAP operating systems.
low complexity
qnap CWE-326
8.8
2023-03-29 CVE-2022-27597 Unspecified vulnerability in Qnap products
A vulnerability has been reported to affect QNAP operating systems.
network
low complexity
qnap
2.7
2023-03-29 CVE-2022-27598 Unspecified vulnerability in Qnap products
A vulnerability has been reported to affect QNAP operating systems.
network
low complexity
qnap
2.7
2023-03-29 CVE-2023-23355 Command Injection vulnerability in Qnap products
An OS command injection vulnerability has been reported to affect QNAP operating systems.
network
low complexity
qnap CWE-77
7.2