cbcvebase.

Qnap Qutscloud vulnerabilities

59 known vulnerabilities affecting qnap/qutscloud.

Total CVEs
59
CISA KEV
0
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL5HIGH36MEDIUM18

Vulnerabilities

Page 1 of 3
CVE-2023-47218P1HIGHCVSS 8.3ExploitedPoC≥ c5.0.0.1919, < c5.1.5.26512024-02-13
CVE-2023-47218 [HIGH] CWE-77 CVE-2023-47218: An OS command injection vulnerability has been reported to affect several QNAP operating system vers An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.5.2645 build 20240116 and later QuTS hero h5.1.5.2647 build 20240118 and later QuTSclou
nvd
CVE-2024-21899P1CRITICALCVSS 9.8Exploitedfixed in c5.1.5.26512024-03-08
CVE-2024-21899 [CRITICAL] CWE-287 CVE-2024-21899: An improper authentication vulnerability has been reported to affect several QNAP operating system v An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build 20231
nvd
CVE-2023-50358P1MEDIUMCVSS 5.8Exploited≥ c5.0.0.1919, < c5.1.5.26512024-02-13
CVE-2023-50358 [MEDIUM] CWE-78 CVE-2023-50358: An OS command injection vulnerability has been reported to affect several QNAP operating system vers An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.5.2645 build 20240116 and later QTS 4.5.4.2627 build 20231225 and later QTS 4.3.6.266
nvd
CVE-2023-23368P1CRITICALCVSS 9.8vc5.0.1.1949vc5.0.1.1998+2 more2023-11-03
CVE-2023-23368 [CRITICAL] CWE-78 CVE-2023-23368: An OS command injection vulnerability has been reported to affect several QNAP operating system vers An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build 20230421 and later QTS 4.5.4.2374 build 20230416 and later QuTS hero h
nvd
CVE-2024-32766P2CRITICALCVSS 10.0≥ c5.0.0.1919, < c5.1.5.26512024-04-26
CVE-2024-32766 [CRITICAL] CWE-77 CVE-2024-32766: An OS command injection vulnerability has been reported to affect several QNAP operating system vers An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h
nvd
CVE-2023-51364P2HIGHCVSS 7.5≥ c5.0.0.1919, < c5.1.5.26512024-04-26
CVE-2023-51364 [HIGH] CWE-22 CVE-2023-51364: A path traversal vulnerability has been reported to affect several QNAP operating system versions. I A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QTS 4.5.4.2627
nvd
CVE-2023-45025P2CRITICALCVSS 9.8vc5.1.0.24982024-02-02
CVE-2023-45025 [CRITICAL] CWE-77 CVE-2023-45025: An OS command injection vulnerability has been reported to affect several QNAP operating system vers An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h
nvd
CVE-2023-51365P2HIGHCVSS 7.5≥ c5.0.0.1919, < c5.1.5.26512024-04-26
CVE-2023-51365 [HIGH] CWE-22 CVE-2023-51365: A path traversal vulnerability has been reported to affect several QNAP operating system versions. I A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QTS 4.5.4.2627
nvd
CVE-2023-39303P2CRITICALCVSS 9.8vc5.1.0.24982024-02-02
CVE-2023-39303 [CRITICAL] CWE-287 CVE-2023-39303: An improper authentication vulnerability has been reported to affect several QNAP operating system v An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QuTS hero h5.1.3.2578 buil
nvd
CVE-2021-44051P2HIGHCVSS 8.8fixed in c5.0.1.19982022-05-05
CVE-2021-44051 [HIGH] CWE-77 CVE-2021-44051: A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero and QTS: QuTScloud c5.0.1.1949 and later QuTS hero h5.0.0.1986 build 20
nvd
CVE-2023-39297P2HIGHCVSS 8.8vc5.1.0.24982024-02-02
CVE-2023-39297 [HIGH] CWE-78 CVE-2023-39297: An OS command injection vulnerability has been reported to affect several QNAP operating system vers An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QTS 4.5.4.2627 build 20231225 and later Q
nvd
CVE-2023-23362P2HIGHCVSS 8.8≥ c5.0.1, ≤ c5.0.1.23742023-09-22
CVE-2023-23362 [HIGH] CWE-78 CVE-2023-23362: An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploit An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability allows remote authenticated users to execute commands via susceptible QNAP devices. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build 20230421 and later QTS 4.5.4.2374 build 20230416 and later
nvd
CVE-2023-47568P3HIGHCVSS 8.8vc5.1.0.24982024-02-02
CVE-2023-47568 [HIGH] CWE-89 CVE-2023-47568: A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.5.2645 build 20240116 and later QTS 4.5.4.2627 build 20231225 and later QuTS
nvd
CVE-2021-28816P3HIGHCVSS 8.8fixed in c4.5.6.17552021-09-10
CVE-2021-28816 [HIGH] CWE-787 CVE-2021-28816: A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QTS, QuTScloud, QuTS hero: QTS 4.5.4.1715 build 20210630 and later QTS 5.0.0.1716 build 20210
nvd
CVE-2021-44052P3HIGHCVSS 8.1fixed in c5.0.1.19982022-05-05
CVE-2021-44052 [HIGH] CWE-59 CVE-2021-44052: An improper link resolution before file access ('Link Following') vulnerability has been reported to An improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, and QTS. If exploited, this vulnerability allows remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. We have already fixed this vul
nvd
CVE-2024-27124P3HIGHCVSS 7.5≥ c5.0.0.1919, < c5.1.5.26512024-04-26
CVE-2024-27124 [HIGH] CWE-78 CVE-2024-27124: An OS command injection vulnerability has been reported to affect several QNAP operating system vers An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h5.1.
nvd
CVE-2024-21900P3MEDIUMCVSS 6.5fixed in c5.1.5.26512024-03-08
CVE-2024-21900 [MEDIUM] CWE-74 CVE-2024-21900: An injection vulnerability has been reported to affect several QNAP operating system versions. If ex An injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QuTS hero h5.1.3.2578 build 20231110 and later QuT
nvd
CVE-2024-21905P3HIGHCVSS 8.2≥ c5.0.0.1919, < c5.1.5.26512024-04-26
CVE-2024-21905 [HIGH] CWE-190 CVE-2024-21905: An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating s An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QuTS hero h5.1.3.2578 b
nvd
CVE-2021-34343P3HIGHCVSS 7.2fixed in c4.5.6.17552021-09-10
CVE-2021-34343 [HIGH] CWE-787 CVE-2021-34343: A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QTS, QuTScloud, QuTS hero: QTS 4.5.4.1715 build 20210630 and later QTS 5.0.0.1716 build 20210
nvd
CVE-2023-23367P3HIGHCVSS 7.2vc5.0.0.1919vc5.0.1.1949+4 more2023-11-10
CVE-2023-23367 [HIGH] CWE-78 CVE-2023-23367: An OS command injection vulnerability has been reported to affect several QNAP operating system vers An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build 20230421 and later QuTS hero h5.0.1.2376 build 2023
nvd
Qnap Qutscloud vulnerabilities | cvebase