Known vulnerabilities in QNAP QTS 4.3.3 build 20180716 - page 3

Software: QNAP QTS
Version: 4.3.3 build 20180716
Software CPE: cpe:2.3:a:qnap_systems:qnap_qts:*:*:*:*:*:*:*:*
Total vulnerabilities: 48
Public exploits: 9
Known exploited (KEV): 8
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting QNAP QTS version 4.3.3 build 20180716 QNAP QTS 4.3.3 build 20180716 is affected by 48 vulnerabilities: 16 high, 21 medium, 11 low Critical High Medium Low

Vulnerabilities (48)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU28117 - Externally Controlled Reference to a Resource in Another Sphere
CVE-2019-7195
CWE-610 High
Public exploit available
Exploited
4.3.6.1070 20190919, 4.4.1.1064 20190918 20.05.2020 SB2019122502
#VU28116 - Externally Controlled Reference to a Resource in Another Sphere
CVE-2019-7194
CWE-610 High
Public exploit available
Exploited
4.3.6.1070 20190919, 4.4.1.1064 20190918 20.05.2020 SB2019122502
#VU16770 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-0713
CWE-79 Low
No
No
4.3.6.0805 20181228 02.01.2019 SB2018122806
#VU16769 - Command injection
CVE-2018-0730
CWE-77 Low
No
No
4.3.6.0805 20181228 02.01.2019 SB2018122806
#VU16039 - Buffer overflow
CVE-2018-14749
CWE-120 High
No
No
4.2.6 20181026, 4.3.3 20181029, 4.3.4 20181026, 4.3.5 20181110 23.11.2018 SB2018112312
#VU16038 - Permissions, Privileges, and Access Controls
CVE-2018-14748
CWE-264 Low
No
No
4.2.6 20181026, 4.3.3 20181029, 4.3.4 20181026, 4.3.5 20181110 23.11.2018 SB2018112312
#VU16037 - Permissions, Privileges, and Access Controls
CVE-2018-14747
CWE-264 Low
No
No
4.2.6 20181026, 4.3.3 20181029, 4.3.4 20181026, 4.3.5 20181110 23.11.2018 SB2018112312
#VU16036 - Command injection
CVE-2018-14746
CWE-77 Low
No
No
4.2.6 20181026, 4.3.3 20181029, 4.3.4 20181026, 4.3.5 20181110 23.11.2018 SB2018112312


Showing elements 41 - 60 out of 48