cbcvebase.

Qnap Systems Inc Qsync Central vulnerabilities

62 known vulnerabilities affecting qnap_systems_inc/qsync_central.

Total CVEs
62
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH19MEDIUM43

Vulnerabilities

Page 1 of 4
CVE-2025-30276P3HIGHCVSS 8.8≥ 5.0.x.x, < 5.0.0.4 ( 2026/01/20 )2026-02-11
CVE-2025-30276 [HIGH] CWE-787 CVE-2025-30276: An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
nvd
CVE-2025-54153P3HIGHCVSS 8.8≥ 5.0.0, < 5.0.0.2 ( 2025/07/31 )2025-10-03
CVE-2025-54153 [HIGH] CWE-89 CVE-2025-54153: An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.2 ( 2025/07/31 ) and later
nvd
CVE-2025-53595P3HIGHCVSS 8.8≥ 5.0.0, < 5.0.0.2 ( 2025/07/31 )2025-10-03
CVE-2025-53595 [HIGH] CWE-89 CVE-2025-53595: An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.2 ( 2025/07/31 ) and later
nvd
CVE-2025-44014P3HIGHCVSS 8.8≥ 4.x, < 5.0.0.1 ( 2025/07/09 )2025-10-03
CVE-2025-44014 [HIGH] CWE-787 CVE-2025-44014: An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.1 ( 2025/07/09 ) and later
nvd
CVE-2025-29893P3HIGHCVSS 8.8≥ 4.5.x.x, < 4.5.0.7 ( 2025/04/23 )2025-08-29
CVE-2025-29893 [HIGH] CWE-89 CVE-2025-29893: An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later
nvd
CVE-2025-29894P3HIGHCVSS 8.8≥ 4.5.x.x, < 4.5.0.7 ( 2025/04/23 )2025-08-29
CVE-2025-29894 [HIGH] CWE-89 CVE-2025-29894: An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later
nvd
CVE-2025-29892P3HIGHCVSS 8.8≥ 4.5.x.x, < 4.5.0.6 ( 2025/03/20 )2025-06-06
CVE-2025-29892 [HIGH] CWE-89 CVE-2025-29892: An SQL injection vulnerability has been reported to affect Qsync Central. If exploited, the vulnerab An SQL injection vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.6 ( 2025/03/20 ) and later
nvd
CVE-2024-50404P3HIGHCVSS 8.8≥ 4.4.x.x, < 4.4.0.16_20240819 ( 2024/08/19 )2024-12-06
CVE-2024-50404 [HIGH] CWE-59 CVE-2024-50404: A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerab A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.16_20240819 ( 2024/08/19 ) and later
nvd
CVE-2025-30277P3HIGHCVSS 8.8≥ 4.5.x.x, < 4.5.0.7 ( 2025/04/23 )2025-08-29
CVE-2025-30277 [HIGH] CWE-295 CVE-2025-30277: An improper certificate validation vulnerability has been reported to affect Qsync Central. If a rem An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later
nvd
CVE-2025-30278P3HIGHCVSS 8.8≥ 4.5.x.x, < 4.5.0.7 ( 2025/04/23 )2025-08-29
CVE-2025-30278 [HIGH] CWE-295 CVE-2025-30278: An improper certificate validation vulnerability has been reported to affect Qsync Central. If a rem An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later
nvd
CVE-2025-22482P3HIGHCVSS 8.1≥ 4.5.x.x, < 4.5.0.6 ( 2025/03/20 )2025-06-06
CVE-2025-22482 [HIGH] CWE-134 CVE-2025-22482: A use of externally-controlled format string vulnerability has been reported to affect Qsync Central A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to obtain secret data or modify memory. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.6 ( 2025/03/20 ) and later
nvd
CVE-2025-30269P3HIGHCVSS 8.1≥ 5.0.x.x, < 5.0.0.4 ( 2026/01/20 )2026-02-11
CVE-2025-30269 [HIGH] CWE-134 CVE-2025-30269: A use of externally-controlled format string vulnerability has been reported to affect Qsync Central A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data or modify memory. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
nvd
CVE-2023-47564P3HIGHCVSS 8.1≥ 4.4.x.x, < 4.4.0.15 ( 2024/01/04 )≥ 4.3.x.x, < 4.3.0.11 ( 2024/01/11 )2024-02-02
CVE-2023-47564 [HIGH] CWE-732 CVE-2023-47564: An incorrect permission assignment for critical resource vulnerability has been reported to affect Q An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.15 ( 2024/01/04 ) and later Qsync Central
nvd
CVE-2025-57709P3HIGHCVSS 8.1≥ 5.0.x.x, < 5.0.0.4 ( 2026/01/20 )2026-02-11
CVE-2025-57709 [HIGH] CWE-122 CVE-2025-57709: A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gain A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
nvd
CVE-2025-52869P3HIGHCVSS 8.1≥ 5.0.x.x, < 5.0.0.4 ( 2026/01/20 )2026-02-11
CVE-2025-52869 [HIGH] CWE-120 CVE-2025-52869: A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gain A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
nvd
CVE-2025-52870P3HIGHCVSS 8.1≥ 5.0.x.x, < 5.0.0.4 ( 2026/01/20 )2026-02-11
CVE-2025-52870 [HIGH] CWE-120 CVE-2025-52870: A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gain A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
nvd
CVE-2025-48723P3HIGHCVSS 8.1≥ 5.0.x.x, < 5.0.0.4 ( 2026/01/20 )2026-02-11
CVE-2025-48723 [HIGH] CWE-120 CVE-2025-48723: A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gain A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
nvd
CVE-2025-48724P3HIGHCVSS 8.1≥ 5.0.x.x, < 5.0.0.4 ( 2026/01/20 )2026-02-11
CVE-2025-48724 [HIGH] CWE-120 CVE-2025-48724: A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gain A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
nvd
CVE-2025-52868P3HIGHCVSS 8.1≥ 5.0.x.x, < 5.0.0.4 ( 2026/01/20 )2026-02-11
CVE-2025-52868 [HIGH] CWE-120 CVE-2025-52868: A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gain A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
nvd
CVE-2025-58470P3MEDIUMCVSS 6.5≥ 5.0.x.x, < 5.0.0.4 ( 2026/01/20 )2026-02-11
CVE-2025-58470 [MEDIUM] CWE-22 CVE-2025-58470: A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
nvd
Qnap Systems Inc Qsync Central vulnerabilities | cvebase