Known vulnerabilities in QNAP QTS - page 13

Software: QNAP QTS
Software CPE: cpe:2.3:a:qnap_systems:qnap_qts:*:*:*:*:*:*:*:*
Total vulnerabilities: 353
Public exploits: 21
Known exploited (KEV): 14
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting QNAP QTS QNAP QTS is affected by 353 known vulnerabilities: 7 critical, 61 high, 121 medium, 164 low Critical High Medium Low

Vulnerabilities (353)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU74200 - Command injection
CVE-2023-23355
CWE-77 Medium
No
No
5.0.1.2346 20230322 30.03.2023 SB2023033031
#VU71996 - Double Free
CVE-2022-4450
CWE-415 Medium
No
No
5.0.1.2346 20230322 07.02.2023 SB2023020742
SB2023020748
SB2023020771
and 180 more
#VU71995 - Use After Free
CVE-2023-0215
CWE-416 Medium
No
No
5.0.1.2346 20230322 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 209 more
#VU71993 - Information Exposure Through Timing Discrepancy
CVE-2022-4304
CWE-208 Medium
No
No
5.0.1.2346 20230322 07.02.2023 SB2023020742
SB2023020748
SB2023020767
and 222 more
#VU71992 - Type confusion
CVE-2023-0286
CWE-843 High
No
No
5.0.1.2346 20230322 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 223 more
#VU71621 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-27596
CWE-89 High
No
No
5.0.1.2234 20221201 30.01.2023 SB2023013013
#VU65827 - Use After Free
CVE-2022-32746
CWE-416 Low
No
No
4.5.4.2125 20220810, 5.0.0.2131 20220815 27.07.2022 SB2022072721
SB2022072728
SB2022072922
and 30 more
#VU65826 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-32745
CWE-835 Medium
No
No
4.5.4.2125 20220810, 5.0.0.2131 20220815 27.07.2022 SB2022072721
SB2022072728
SB2022072922
and 19 more
#VU65825 - Permissions, Privileges, and Access Controls
CVE-2022-32744
CWE-264 Low
No
No
4.5.4.2125 20220810, 5.0.0.2131 20220815 27.07.2022 SB2022072721
SB2022072728
SB2022072922
and 20 more
#VU65824 - Missing release of memory after effective lifetime
CVE-2022-32742
CWE-401 Low
No
No
4.5.4.2125 20220810, 5.0.0.2131 20220815 27.07.2022 SB2022072721
SB2022072728
SB2022072922
and 36 more
#VU65820 - Permissions, Privileges, and Access Controls
CVE-2022-2031
CWE-264 Medium
No
No
4.5.4.2125 20220810, 5.0.0.2131 20220815 27.07.2022 SB2022072721
SB2022072728
SB2022072922
and 15 more
#VU64089 - Improper Authentication
CVE-2022-31813
CWE-287 Medium
No
No
4.5.4.2125 20220810, 5.0.0.2131 20220815 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 49 more
#VU64088 - Out-of-bounds read
CVE-2022-30556
CWE-125 Medium
No
No
4.5.4.2125 20220810, 5.0.0.2131 20220815 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 31 more
#VU64086 - Resource exhaustion
CVE-2022-30522
CWE-400 Medium
No
No
4.5.4.2125 20220810, 5.0.0.2131 20220815 08.06.2022 SB2022060817
SB2022060901
SB2022061723
and 31 more
#VU64085 - Improper input validation
CVE-2022-29404
CWE-20 Medium
No
No
4.5.4.2125 20220810, 5.0.0.2131 20220815 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 30 more
#VU64083 - Out-of-bounds read
CVE-2022-28615
CWE-125 Low
No
No
4.5.4.2125 20220810, 5.0.0.2131 20220815 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 41 more
#VU64081 - Out-of-bounds read
CVE-2022-28614
CWE-125 Low
No
No
4.5.4.2125 20220810, 5.0.0.2131 20220815 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 36 more
#VU64080 - Out-of-bounds read
CVE-2022-28330
CWE-125 Medium
No
No
4.5.4.2125 20220810, 5.0.0.2131 20220815 08.06.2022 SB2022060817
SB2022060901
SB2022070730
and 11 more
#VU64078 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-26377
CWE-444 Medium
Available
No
4.5.4.2125 20220810, 5.0.0.2131 20220815 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 39 more
#VU22304 - Memory corruption
CVE-2019-11043
CWE-119 High
Available
Exploited
5.0.1.2034 20220515 27.10.2019 SB2019102707
SB2019102708
SB2019102709
and 22 more


Showing elements 241 - 260 out of 353