cbcvebase.

Qnap Quts Hero vulnerabilities

234 known vulnerabilities affecting qnap/quts_hero.

Total CVEs
234
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
6
Severity breakdown
CRITICAL15HIGH107MEDIUM109LOW3

Vulnerabilities

Page 12 of 12
CVE-2025-53590P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+16 more2026-01-02
CVE-2025-53590 [MEDIUM] CWE-476 CVE-2025-53590: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and late
nvd
CVE-2024-37048P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+5 more2024-11-22
CVE-2024-37048 [MEDIUM] CWE-476 CVE-2024-37048: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 an
nvd
CVE-2023-32970P4MEDIUMCVSS 4.9≥ h4.5.0, < h4.5.4.2476≥ h5.0.0, < h5.0.1.2515+1 more2023-10-13
CVE-2023-32970 [MEDIUM] CWE-476 CVE-2023-32970: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to launch a denial-of-service (DoS) attack via a network. QES is not affected. We have already fixed the vulnerability in the following versions: QuTS hero h5.0.1.2515
nvd
CVE-2023-45028P4MEDIUMCVSS 4.9vh5.1.0.2409vh5.1.0.2424+7 more2024-02-02
CVE-2023-45028 [MEDIUM] CWE-400 CVE-2023-45028: An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operatin An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to launch a denial-of-service (DoS) attack via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.5.2645 build 20240116 and
nvd
CVE-2023-39301P4MEDIUMCVSS 4.3fixed in h5.1.1.2488fixed in h5.0.1.25152023-11-03
CVE-2023-39301 [MEDIUM] CWE-918 CVE-2023-39301: A server-side request forgery (SSRF) vulnerability has been reported to affect several QNAP operatin A server-side request forgery (SSRF) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to read application data via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2514 build 20230906 and later QTS 5.1.1.2491 build
nvd
CVE-2024-37042P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+5 more2024-11-22
CVE-2024-37042 [MEDIUM] CWE-476 CVE-2024-37042: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 an
nvd
CVE-2024-37045P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+5 more2024-11-22
CVE-2024-37045 [MEDIUM] CWE-476 CVE-2024-37045: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 an
nvd
CVE-2023-41274P4MEDIUMCVSS 4.9vh5.1.0.2409vh5.1.0.2424+4 more2024-02-02
CVE-2023-41274 [MEDIUM] CWE-476 CVE-2023-41274: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to launch a denial-of-service (DoS) attack via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.2.2533 build 20230926 and later QuT
nvd
CVE-2023-32969P4MEDIUMCVSS 4.8≥ h5.1.0, < h5.1.4.2596vh5.1.4.25962024-03-08
CVE-2023-32969 [MEDIUM] CWE-79 CVE-2023-32969: A cross-site scripting (XSS) vulnerability has been reported to affect Network & Virtual Switch. If A cross-site scripting (XSS) vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QuTScloud c5.1.5.2651 and later QTS 5.1.4.2596 build 20231128 and later QuT
nvd
CVE-2023-50366P4MEDIUMCVSS 4.8vh5.1.0.2409vh5.1.0.2424+8 more2024-09-06
CVE-2023-50366 [MEDIUM] CWE-79 CVE-2023-50366: A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.273
nvd
CVE-2024-32765P4MEDIUMCVSS 4.2≥ h5.1.0, < h5.1.8.28232024-08-12
CVE-2024-32765 [MEDIUM] CWE-291 CVE-2024-32765: A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerabilit A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow local authenticated administrators to gain access to and execute certain functions via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QuTS hero h5.1.8.2823
nvd
CVE-2024-32771P4LOWCVSS 2.4vh5.1.0.2409vh5.1.0.2424+14 more2024-09-06
CVE-2024-32771 [LOW] CWE-307 CVE-2024-32771: An improper restriction of excessive authentication attempts vulnerability has been reported to affe An improper restriction of excessive authentication attempts vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local network authenticated administrators to perform an arbitrary number of authentication attempts via unspecified vectors. QuTScloud is not affected. We have alrea
nvd
CVE-2022-27598P4LOWCVSS 2.7fixed in h5.0.1.23482023-03-29
CVE-2022-27598 [LOW] CWE-125 CVE-2022-27598: A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret values. The vulnerability affects the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances) We have already fixed the vulnerability in the followin
nvd
CVE-2022-27597P4LOWCVSS 2.7fixed in h5.0.1.23482023-03-29
CVE-2022-27597 [LOW] CWE-125 CVE-2022-27597: A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret values. The vulnerability affects the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances) We have already fixed the vulnerability in the followin
nvd
Qnap Quts Hero vulnerabilities | cvebase