cbcvebase.

Qnap Quts Hero vulnerabilities

234 known vulnerabilities affecting qnap/quts_hero.

Total CVEs
234
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
6
Severity breakdown
CRITICAL15HIGH107MEDIUM109LOW3

Vulnerabilities

Page 8 of 12
CVE-2025-62852P3MEDIUMCVSS 6.5vh5.2.0.2737vh5.2.0.2782+18 more2026-01-02
CVE-2025-62852 [MEDIUM] CWE-121 CVE-2025-62852: A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: QTS 5.2.8.3332 build 20251128 and later
nvd
CVE-2025-47208P3MEDIUMCVSS 6.5vh5.2.0.2737vh5.2.0.2782+16 more2026-01-02
CVE-2025-47208 [MEDIUM] CWE-770 CVE-2025-47208: An allocation of resources without limits or throttling vulnerability has been reported to affect se An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerab
nvd
CVE-2025-30265P3MEDIUMCVSS 6.5vh5.2.0.2737vh5.2.0.2782+11 more2025-08-29
CVE-2025-30265 [MEDIUM] CWE-120 CVE-2025-30265: A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 bu
nvd
CVE-2025-53592P3MEDIUMCVSS 6.5vh5.2.0.2737vh5.2.0.2782+16 more2026-01-02
CVE-2025-53592 [MEDIUM] CWE-476 CVE-2025-53592: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS he
nvd
CVE-2025-44013P3MEDIUMCVSS 6.5vh5.2.0.2737vh5.2.0.2782+16 more2026-01-02
CVE-2025-44013 [MEDIUM] CWE-476 CVE-2025-44013: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and later QuTS he
nvd
CVE-2024-53692P3MEDIUMCVSS 4.7vh5.2.0.2737vh5.2.0.2782+8 more2025-03-07
CVE-2024-53692 [MEDIUM] CWE-77 CVE-2024-53692: A command injection vulnerability has been reported to affect several QNAP operating system versions A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later QuTS hero h5.
nvd
CVE-2025-29882P3MEDIUMCVSS 6.5vh5.2.0.2737vh5.2.0.2782+11 more2025-08-29
CVE-2025-29882 [MEDIUM] CWE-476 CVE-2025-29882: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS he
nvd
CVE-2025-30267P3MEDIUMCVSS 6.5vh5.2.0.2737vh5.2.0.2782+11 more2025-08-29
CVE-2025-30267 [MEDIUM] CWE-476 CVE-2025-30267: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS he
nvd
CVE-2025-30268P3MEDIUMCVSS 6.5vh5.2.0.2737vh5.2.0.2782+11 more2025-08-29
CVE-2025-30268 [MEDIUM] CWE-476 CVE-2025-30268: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS he
nvd
CVE-2023-51368P4MEDIUMCVSS 6.5vh5.1.0.2409vh5.1.0.2424+8 more2024-09-06
CVE-2023-51368 [MEDIUM] CWE-476 CVE-2023-51368: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to launch a denial-of-service (DoS) attack via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 buil
nvd
CVE-2025-30274P4MEDIUMCVSS 6.5vh5.2.0.2737vh5.2.0.2782+11 more2025-08-29
CVE-2025-30274 [MEDIUM] CWE-476 CVE-2025-30274: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later
nvd
CVE-2025-30272P4MEDIUMCVSS 6.5vh5.2.0.2737vh5.2.0.2782+11 more2025-08-29
CVE-2025-30272 [MEDIUM] CWE-476 CVE-2025-30272: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later
nvd
CVE-2025-59380P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+18 more2026-01-02
CVE-2025-59380 [MEDIUM] CWE-22 CVE-2025-59380: A path traversal vulnerability has been reported to affect several QNAP operating system versions. I A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3332 build 20251128 and l
nvd
CVE-2024-56805P4MEDIUMCVSS 5.4vh5.2.0.2737vh5.2.0.2782+10 more2025-06-06
CVE-2024-56805 [MEDIUM] CWE-120 CVE-2024-56805: A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.4.3079 build 20250321 and later QuTS hero h5.2.4.3
nvd
CVE-2025-47211P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+12 more2025-10-03
CVE-2025-47211 [MEDIUM] CWE-22 CVE-2025-47211: A path traversal vulnerability has been reported to affect several QNAP operating system versions. I A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and l
nvd
CVE-2025-59381P4MEDIUMCVSS 4.9vh5.2.0.2737-build_20240417vh5.2.0.2782-build_20240601+18 more2026-01-02
CVE-2025-59381 [MEDIUM] CWE-22 CVE-2025-59381: A path traversal vulnerability has been reported to affect several QNAP operating system versions. I A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3332 build 20251128 and l
nvd
CVE-2024-21906P4MEDIUMCVSS 4.7vh5.1.0.2409vh5.1.0.2424+12 more2024-09-06
CVE-2024-21906 [MEDIUM] CWE-78 CVE-2024-21906: An OS command injection vulnerability has been reported to affect several QNAP operating system vers An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QuTS hero h5.1.8.2823 build 20
nvd
CVE-2024-21903P4MEDIUMCVSS 4.7vh5.1.0.2409vh5.1.0.2424+8 more2024-09-06
CVE-2024-21903 [MEDIUM] CWE-77 CVE-2024-21903: An OS command injection vulnerability has been reported to affect several QNAP operating system vers An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 build 20
nvd
CVE-2025-33032P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+11 more2025-08-29
CVE-2025-33032 [MEDIUM] CWE-22 CVE-2025-33032: A path traversal vulnerability has been reported to affect several QNAP operating system versions. I A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: QTS 5.2.5.3145 build 20250526 and la
nvd
CVE-2021-38693P4MEDIUMCVSS 5.3≥ h5.0.0.1772, < h5.0.0.19492022-05-05
CVE-2021-38693 [MEDIUM] CWE-22 CVE-2021-38693: A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Appliance. If exploited, this vulnerability allows attackers to read the contents of unexpected files and expose sensitive data. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero, QTS, QVR Pro Appl
nvd
Qnap Quts Hero vulnerabilities | cvebase