Known vulnerabilities in QNAP QTS - page 14

Software: QNAP QTS
Software CPE: cpe:2.3:a:qnap_systems:qnap_qts:*:*:*:*:*:*:*:*
Total vulnerabilities: 353
Public exploits: 21
Known exploited (KEV): 14
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting QNAP QTS QNAP QTS is affected by 353 known vulnerabilities: 7 critical, 61 high, 121 medium, 164 low Critical High Medium Low

Vulnerabilities (353)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU62841 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2021-44054
CWE-601 Medium
No
No
4.2.6 20220304, 4.3.3.1945 20220303, 4.3.4.1976 20220303, 4.3.6.1965 20220302, 4.5.4.1991 20220329, 5.0.0.1986 20220324 06.05.2022 SB2022050605
#VU62840 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-44053
CWE-79 Low
No
No
4.2.6 20220304, 4.3.3.1945 20220303, 4.3.4.1976 20220303, 4.3.6.1965 20220302, 4.5.4.1991 20220329, 5.0.0.1986 20220324 06.05.2022 SB2022050605
#VU62839 - Improper Link Resolution Before File Access ('Link Following')
CVE-2021-44052
CWE-59 High
No
No
4.2.6 20220304, 4.3.3.1945 20220303, 4.3.4.1976 20220303, 4.3.6.1965 20220302, 4.5.4.1991 20220329, 5.0.0.1986 20220324 06.05.2022 SB2022050605
#VU62838 - Command injection
CVE-2021-44051
CWE-77 High
No
No
4.2.6 20220304, 4.3.3.1945 20220303, 4.3.4.1976 20220303, 4.3.6.1965 20220302, 4.5.4.1991 20220329, 5.0.0.1986 20220324 06.05.2022 SB2022050605
#VU62837 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-38693
CWE-22 Medium
No
No
4.5.4.1991 20220329, 5.0.0.1986 20220324 06.05.2022 SB2022050604
#VU61622 - Out-of-bounds read
CVE-2022-23124
CWE-125 Medium
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 5 more
#VU61621 - Out-of-bounds read
CVE-2022-23123
CWE-125 Medium
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 6 more
#VU61620 - Improper Handling of Exceptional Conditions
CVE-2022-23121
CWE-755 High
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 7 more
#VU61619 - Stack-based buffer overflow
CVE-2022-23125
CWE-121 High
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 6 more
#VU61618 - Stack-based buffer overflow
CVE-2022-23122
CWE-121 High
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 5 more
#VU61617 - Stack-based buffer overflow
CVE-2022-0194
CWE-121 High
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 5 more
#VU60526 - Improper Authentication
CVE-2021-38679
CWE-287 High
No
No
- 11.02.2022 SB2022021101
#VU58098 - Improper Access Control
CVE-2016-2124
CWE-284 High
No
No
5.0.0.1891 20211221 10.11.2021 SB2021111008
SB2021111201
SB2021112913
and 34 more
#VU58097 - Permissions, Privileges, and Access Controls
CVE-2020-25717
CWE-264 Medium
No
No
5.0.0.1891 20211221 10.11.2021 SB2021111008
SB2021111201
SB2021112913
and 43 more
#VU58096 - Permissions, Privileges, and Access Controls
CVE-2020-25718
CWE-264 Medium
No
No
5.0.0.1891 20211221 10.11.2021 SB2021111008
SB2021111201
SB2022012012
and 11 more
#VU58095 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2020-25719
CWE-362 Low
No
No
5.0.0.1891 20211221 10.11.2021 SB2021111008
SB2021111201
SB2021121644
and 17 more
#VU58094 - Improper Authentication
CVE-2020-25721
CWE-287 Medium
No
No
5.0.0.1891 20211221 10.11.2021 SB2021111008
SB2021111201
SB2022012012
and 13 more
#VU58093 - Permissions, Privileges, and Access Controls
CVE-2020-25722
CWE-264 Medium
No
No
5.0.0.1891 20211221 10.11.2021 SB2021111008
SB2021111201
SB2021113012
and 14 more
#VU58092 - Use After Free
CVE-2021-3738
CWE-416 Medium
No
No
5.0.0.1891 20211221 10.11.2021 SB2021111008
SB2021111201
SB2022012012
and 11 more
#VU52802 - Heap-based Buffer Overflow
CVE-2021-31439
CWE-122 Medium
No
No
4.5.4.2012 20220419 03.05.2021 SB2021050308
SB2022042577
SB2022042578
and 6 more


Showing elements 261 - 280 out of 353