Vulnerabilities > Qnap > QTS

DATE CVE VULNERABILITY TITLE RISK
2021-09-10 CVE-2018-19957 Improper Restriction of Rendered UI Layers or Frames vulnerability in Qnap Qts, Quts Hero and Qutscloud
A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS running QTS, QuTS hero, and QuTScloud.
network
low complexity
qnap CWE-1021
6.1
2021-09-10 CVE-2021-28816 Out-of-bounds Write vulnerability in Qnap Qts, Quts Hero and Qutscloud
A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero.
network
low complexity
qnap CWE-787
8.8
2021-09-10 CVE-2021-34343 Out-of-bounds Write vulnerability in Qnap Qts, Quts Hero and Qutscloud
A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero.
network
low complexity
qnap CWE-787
7.2
2021-07-01 CVE-2020-36194 Cross-site Scripting vulnerability in Qnap QTS and Quts Hero
An XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero.
network
low complexity
qnap CWE-79
6.1
2021-07-01 CVE-2021-28802 OS Command Injection vulnerability in Qnap QTS and Quts Hero
A command injection vulnerabilities have been reported to affect QTS and QuTS hero.
network
low complexity
qnap CWE-78
critical
9.8
2021-07-01 CVE-2021-28804 OS Command Injection vulnerability in Qnap QTS and Quts Hero
A command injection vulnerabilities have been reported to affect QTS and QuTS hero.
network
low complexity
qnap CWE-78
critical
9.8
2021-06-24 CVE-2021-28800 OS Command Injection vulnerability in Qnap QTS
A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QTS.
network
low complexity
qnap CWE-78
critical
9.8
2021-06-03 CVE-2021-28806 Cross-site Scripting vulnerability in Qnap QTS
A DOM-based XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero.
network
low complexity
qnap CWE-79
5.4
2021-05-21 CVE-2021-28798 Path Traversal vulnerability in Qnap QTS and Quts Hero
A relative path traversal vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero.
network
low complexity
qnap CWE-22
7.5
2021-04-17 CVE-2020-36195 SQL Injection vulnerability in Qnap QTS
An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on.
network
low complexity
qnap CWE-89
critical
9.8