Vulnerabilidades em QNAP

36 resultados
Análise Vexday

QNAP registra 36 vulnerabilidades na base do Vexday, mas nenhuma está sob ataque ativo (KEV) ou classificada como crítica. Não há publicações recentes nos últimos 90 dias, indicando que o risco presente é histórico e não representa ameaça imediata. O panorama sugere estabilidade relativa na postura de segurança atual do fornecedor.

CVE-2018-0722Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier inEPSS 1.7%CVE-2018-0718Command injection vulnerability in Music Station 5.1.2 and earlier versions in QNAP QTS 4.3.3 and 4.3.4 could allow remote attackers to run EPSS 1.7%CVE-2017-13071QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on the QNAP Video StatEPSS 1.4%CVE-2017-7633QNAP Qfinder Pro 6.1.0.0317 and earlier may expose sensitive information contained in NAS devices. If exploited, this may allow attackers toEPSS 1.3%CVE-2018-14748Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 201808EPSS 1.3%CVE-2018-14747NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 2018EPSS 1.3%CVE-2018-14749Buffer Overflow vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and EPSS 1.2%CVE-2018-0711Cross-site scripting (XSS) vulnerability in QNAP QTS 4.3.3 build 20180126, QTS 4.3.4 build 20180315, and their earlier versions could allow EPSS 0.9%CVE-2017-13072Cross-site scripting (XSS) vulnerability in App Center in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20171213, QTS 4.3.4 build 20171223,EPSS 0.8%CVE-2017-13073Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allowEPSS 0.8%CVE-2017-7634Cross-site scripting (XSS) vulnerability in QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remEPSS 0.8%CVE-2018-0724Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote attackers to inject EPSS 0.8%CVE-2018-0723Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote attackers to inject EPSS 0.8%CVE-2018-0716Cross-site scripting vulnerability in QTS 4.2.6 build 20180711, QTS 4.3.3: Qsync Central 3.0.2, QTS 4.3.4: Qsync Central 3.0.3, QTS 4.3.5: QEPSS 0.8%CVE-2017-7638QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exEPSS 0.7%CVE-2017-7641QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not utilize CSRF protections.EPSS 0.5%