Vulnerabilities > Qnap > Critical

DATE CVE VULNERABILITY TITLE RISK
2016-02-27 CVE-2015-6022 Unspecified vulnerability in Qnap Signage Station 2.0
Unrestricted file upload vulnerability in QNAP Signage Station before 2.0.1 allows remote authenticated users to execute arbitrary code by uploading an executable file, and then accessing this file via an unspecified URL.
network
low complexity
qnap
critical
9.0
2015-10-16 CVE-2015-6003 Path Traversal vulnerability in Qnap QTS
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.
network
qnap CWE-22
critical
9.3