VendorsQNAPqts4.3.6
Vulnerabilities

QNAP QTS 4.3.6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2022-27593
DeadBolt Ransomware
Published 2022-09-08 · Analyzed
10.0KEVEPSS 0.879
CVE-2021-28799
Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)
Published 2021-05-13 · Analyzed
10.0KEVEPSS 0.783
CVE-2021-28809
Missing Authentication for Critical Function in RTRR Server in HBS3
Published 2021-07-08 · Modified
10.0EPSS 0.158
CVE-2020-2509
Command Injection Vulnerability in QTS and QuTS hero
Published 2021-04-17 · Analyzed
9.8KEVEPSS 0.334
CVE-2018-0729
This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating Music Station to their latest versions.
Published 2019-12-04 · Modified
9.8EPSS 0.023
CVE-2018-19950
If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.
Published 2020-11-02 · Modified
9.8EPSS 0.021
CVE-2020-36195
SQL Injection Vulnerability in Multimedia Console and the Media Streaming Add-On
Published 2021-04-17 · Modified
9.8EPSS 0.018
CVE-2021-34344
Stack Buffer Overflow Vulnerability in QUSBCam2
Published 2021-09-10 · Modified
9.8EPSS 0.016
CVE-2021-38687
Stack Overflow Vulnerability in Surveillance Station
Published 2021-12-29 · Modified
9.8EPSS 0.013
CVE-2020-36197
Improper Access Control Vulnerability in Music Station
Published 2021-05-13 · Modified
8.8EPSS 0.185
CVE-2021-34362
Command Injection Vulnerability in Media Streaming Add-on
Published 2021-10-22 · Modified
8.7EPSS 0.013
CVE-2021-28807
Post-Authentication Reflected XSS Vulnerability in Q'center
Published 2021-06-03 · Modified
7.7EPSS 0.014
CVE-2018-19952
If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.
Published 2020-11-02 · Modified
7.5EPSS 0.013
CVE-2020-2491
Cross-site Scripting Vulnerability in Photo Station
Published 2020-12-10 · Modified
6.1EPSS 0.010
CVE-2018-19951
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.
Published 2020-11-02 · Modified
6.1EPSS 0.008
CVE-2018-19942
Cross-site Scripting Vulnerability in File Station
Published 2021-04-16 · Modified
6.1EPSS 0.007
CVE-2019-7197
A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS. If exploited, this vulnerability may allow an attacker to inject and execute scripts on the administrator console. To fix this vulnerability, QNAP recommend updating QTS to the latest version.
Published 2019-12-04 · Modified
4.8EPSS 0.012