Known vulnerabilities in Media Streaming add-on
Vendor:
QNAP Systems, Inc.
Software:
Media Streaming add-on
Software CPE:
cpe:2.3:a:qnap_systems:media_streaming_add-on:*:*:*:*:*:*:*:*
Website:
https://www.qnap.com
Total vulnerabilities:
6
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU124219 - Stack-based buffer overflow CVE-2025-59383 |
CWE-121 | Medium | 500.1.1 | 23.03.2026 |
SB2026032342 |
||
| #VU100888 - Authorization Bypass Through User-Controlled Key CVE-2024-50395 |
CWE-639 | Medium | 500.1.1.6 | 25.11.2024 |
SB2024112524 |
||
| #VU89043 - Exposure of sensitive information to an unauthorized actor CVE-2023-47222 |
CWE-200 | Medium | 500.1.1.5 | 29.04.2024 |
SB2024042922 |
||
| #VU82728 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2023-23369 |
CWE-78 | High | 500.0.0.11, 500.1.1.2 | 06.11.2023 |
SB2023110611 |
||
| #VU57599 - Command injection CVE-2021-34362 |
CWE-77 | High | 430.1.8.12, 500.0.0.3 | 22.10.2021 |
SB2021102202 |
||
| #VU52491 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2020-36195 |
CWE-89 | Medium | 430.1.8.8, 430.1.8.10 | 22.04.2021 |
SB2021042203 |