cbcvebase.

Qnap Quts Hero vulnerabilities

234 known vulnerabilities affecting qnap/quts_hero.

Total CVEs
234
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
6
Severity breakdown
CRITICAL15HIGH107MEDIUM109LOW3

Vulnerabilities

Page 10 of 12
CVE-2018-19942P4MEDIUMCVSS 6.1fixed in h4.5.1vh4.5.12021-04-16
CVE-2018-19942 [MEDIUM] CWE-79 CVE-2018-19942: A cross-site scripting (XSS) vulnerability has been reported to affect earlier versions of File Stat A cross-site scripting (XSS) vulnerability has been reported to affect earlier versions of File Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 build 20210202 (and later) QTS 4.5.1.1456 build 20201015 (and later) QTS 4.3.6.14
nvd
CVE-2021-44053P4MEDIUMCVSS 6.1fixed in h4.5.4.1771≥ h5.0.0.1772, < h5.0.0.19862022-05-05
CVE-2021-44053 [MEDIUM] CWE-79 CVE-2021-44053: A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QTS, QuTS A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QTS, QuTS hero and QuTScloud: QTS 4.5.4.1991 build 20220329 and later QTS 5.0.
nvd
CVE-2021-38674P4MEDIUMCVSS 6.1fixed in h4.5.4.17712022-01-07
CVE-2021-38674 [MEDIUM] CWE-79 CVE-2021-38674: A cross-site scripting (XSS) vulnerability has been reported to affect QTS, QuTS hero and QuTScloud. A cross-site scripting (XSS) vulnerability has been reported to affect QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QTS, QuTS hero and QuTScloud: QuTS hero h4.5.4.1771 build 20210825 and later QTS 4.5.4.1787 build
nvd
CVE-2021-44054P4MEDIUMCVSS 6.1fixed in h4.5.4.1771≥ h5.0.0.1772, < h5.0.0.19862022-05-05
CVE-2021-44054 [MEDIUM] CWE-601 CVE-2021-44054: An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows attackers to redirect users to an untrusted page that contains malware. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero and QTS: QuTScloud c5.0.1.1949 and later
nvd
CVE-2025-58466P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+16 more2026-02-11
CVE-2025-58466 [MEDIUM] CWE-457 CVE-2025-58466: A use of uninitialized variable vulnerability has been reported to affect several QNAP operating sys A use of uninitialized variable vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to denial of service conditions, or modify control flow in unexpected ways. We have already fixed the vulnerability in the following versions:
nvd
CVE-2024-53696P4MEDIUMCVSS 4.9≥ h4.5.0, < h4.5.4.24762025-03-07
CVE-2024-53696 [MEDIUM] CWE-918 CVE-2024-53696: A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If expl A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read application data. We have already fixed the vulnerability in the following versions: QuLog Center 1.7.0.829 ( 2024/10/01 ) and later QuLog Center 1.8.0
nvd
CVE-2020-2495P4MEDIUMCVSS 6.1fixed in 4.5.1.14722020-12-10
CVE-2020-2495 [MEDIUM] CWE-79 CVE-2020-2495: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicio If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later QTS 4.3.
nvd
CVE-2020-2496P4MEDIUMCVSS 6.1fixed in 4.5.1.14722020-12-10
CVE-2020-2496 [MEDIUM] CWE-79 CVE-2020-2496: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicio If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later QTS 4.3.
nvd
CVE-2020-2497P4MEDIUMCVSS 6.1fixed in 4.5.1.14722020-12-10
CVE-2020-2497 [MEDIUM] CWE-79 CVE-2020-2497: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicio If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in System Connection Logs. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and late
nvd
CVE-2020-2498P4MEDIUMCVSS 6.1fixed in h4.5.1.14722020-12-10
CVE-2020-2498 [MEDIUM] CWE-79 CVE-2020-2498: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicio If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in certificate configuration. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and l
nvd
CVE-2025-47205P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+15 more2026-02-11
CVE-2025-47205 [MEDIUM] CWE-476 CVE-2025-47205: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3332 build 20251128 and lat
nvd
CVE-2025-66274P4MEDIUMCVSS 4.9vh5.3.0.3115-build_20250430vh5.3.0.3145-build_20250530+3 more2026-02-11
CVE-2025-66274 [MEDIUM] CWE-476 CVE-2025-66274: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and lat
nvd
CVE-2025-52426P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+16 more2026-01-02
CVE-2025-52426 [MEDIUM] CWE-476 CVE-2025-52426: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and lat
nvd
CVE-2025-53414P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+16 more2026-01-02
CVE-2025-53414 [MEDIUM] CWE-476 CVE-2025-53414: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and lat
nvd
CVE-2025-53596P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+16 more2026-01-02
CVE-2025-53596 [MEDIUM] CWE-476 CVE-2025-53596: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and lat
nvd
CVE-2025-53589P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+16 more2026-01-02
CVE-2025-53589 [MEDIUM] CWE-476 CVE-2025-53589: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and lat
nvd
CVE-2025-53405P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+16 more2026-01-02
CVE-2025-53405 [MEDIUM] CWE-476 CVE-2025-53405: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and lat
nvd
CVE-2025-52430P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+16 more2026-01-02
CVE-2025-52430 [MEDIUM] CWE-476 CVE-2025-52430: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and lat
nvd
CVE-2025-52431P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+16 more2026-01-02
CVE-2025-52431 [MEDIUM] CWE-476 CVE-2025-52431: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and lat
nvd
CVE-2025-47213P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+12 more2025-10-03
CVE-2025-47213 [MEDIUM] CWE-476 CVE-2025-47213: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and lat
nvd