cbcvebase.

Qnap Q Center vulnerabilities

7 known vulnerabilities affecting qnap/q_center.

Total CVEs
7
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2018-0706P2HIGHCVSS 8.8PoC≤ 1.7.10632018-07-17
CVE-2018-0706 [HIGH] CVE-2018-0706: Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier coul Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to access sensitive information.
nvd
CVE-2018-0708P2HIGHCVSS 8.8PoC≤ 1.7.10632018-07-17
CVE-2018-0708 [HIGH] CWE-78 CVE-2018-0708: Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 an Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.
nvd
CVE-2018-0707P2HIGHCVSS 7.2PoC≤ 1.7.10632018-07-17
CVE-2018-0707 [HIGH] CWE-78 CVE-2018-0707: Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.10 Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.
nvd
CVE-2018-0710P2HIGHCVSS 8.8PoC≤ 1.7.10632018-07-17
CVE-2018-0710 [HIGH] CWE-78 CVE-2018-0710: Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earli Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.
nvd
CVE-2018-0709P2HIGHCVSS 8.8PoC≤ 1.7.10632018-07-17
CVE-2018-0709 [HIGH] CWE-78 CVE-2018-0709: Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earl Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.
nvd
CVE-2021-28807P4MEDIUMCVSS 5.4fixed in 1.12.1012fixed in 1.10.10042021-06-03
CVE-2021-28807 [MEDIUM] CWE-79 CVE-2021-28807: A post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’cen A post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’center. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already fixed this vulnerability in the following versions of Q’center: QTS 4.5.3: Q’center v1.12.1012 and later QTS 4.3.6: Q’center v1.10.1004 and later
nvd
CVE-2021-28803P4MEDIUMCVSS 5.4fixed in 1.11.10042021-07-01
CVE-2021-28803 [MEDIUM] CWE-80 CVE-2021-28803: This issue affects: QNAP Systems Inc. Q'center versions prior to 1.11.1004. This issue affects: QNAP Systems Inc. Q'center versions prior to 1.11.1004.
nvd
Qnap Q Center vulnerabilities | cvebase