Known vulnerabilities in QNAP QTS - page 7

Software: QNAP QTS
Software CPE: cpe:2.3:a:qnap_systems:qnap_qts:*:*:*:*:*:*:*:*
Total vulnerabilities: 353
Public exploits: 21
Known exploited (KEV): 14
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting QNAP QTS QNAP QTS is affected by 353 known vulnerabilities: 7 critical, 61 high, 121 medium, 164 low Critical High Medium Low

Vulnerabilities (353)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU100900 - Use of Externally-Controlled Format String
CVE-2024-50397
CWE-134 High
No
No
5.2.1.2930 20241025 25.11.2024 SB2024112526
#VU100899 - Use of Externally-Controlled Format String
CVE-2024-50396
CWE-134 High
No
No
5.2.1.2930 20241025 25.11.2024 SB2024112526
#VU100898 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-37046
CWE-22 Low
No
No
5.2.1.2930 20241025 25.11.2024 SB2024112526
#VU100896 - NULL Pointer Dereference
CVE-2024-37048
CWE-476 Low
No
No
5.2.1.2930 20241025 25.11.2024 SB2024112526
#VU100895 - NULL Pointer Dereference
CVE-2024-37045
CWE-476 Low
No
No
5.2.1.2930 20241025 25.11.2024 SB2024112526
#VU100894 - NULL Pointer Dereference
CVE-2024-37042
CWE-476 Low
No
No
5.2.1.2930 20241025 25.11.2024 SB2024112526
#VU100893 - Memory corruption
CVE-2024-37050
CWE-119 Low
No
No
5.2.1.2930 20241025 25.11.2024 SB2024112526
#VU100892 - Memory corruption
CVE-2024-37049
CWE-119 Low
No
No
5.2.1.2930 20241025 25.11.2024 SB2024112526
#VU100891 - Memory corruption
CVE-2024-37047
CWE-119 Low
No
No
5.2.1.2930 20241025 25.11.2024 SB2024112526
#VU100890 - Memory corruption
CVE-2024-37044
CWE-119 Low
No
No
5.2.1.2930 20241025 25.11.2024 SB2024112526
#VU100889 - Memory corruption
CVE-2024-37041
CWE-119 Low
No
No
5.2.1.2930 20241025 25.11.2024 SB2024112526
#VU96963 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-39300
CWE-78 Low
No
No
4.2.6 20240618, 4.3.3.2784 20240619, 4.3.4.2814 20240618, 4.3.6.2805 20240619 09.09.2024 SB2024090955
#VU96962 - Improper Authorization
CVE-2023-39298
CWE-285 Low
No
No
5.2.0.2782 20240601 09.09.2024 SB2024090952
#VU96961 - Improper Restriction of Excessive Authentication Attempts
CVE-2024-32771
CWE-307 Low
No
No
5.2.0.2782 20240601 09.09.2024 SB2024090952
#VU96960 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-34979
CWE-78 Low
No
No
4.5.4.2790 20240605 09.09.2024 SB2024090951
#VU96959 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-34974
CWE-78 Medium
No
No
4.5.4.2790 20240605 09.09.2024 SB2024090951
#VU96958 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-21906
CWE-78 Low
No
No
5.1.8.2823 20240712 09.09.2024 SB2024090950
#VU96957 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-38641
CWE-78 Low
No
No
5.1.8.2823 20240712 09.09.2024 SB2024090950
#VU96956 - Memory corruption
CVE-2024-32763
CWE-119 Medium
No
No
5.1.8.2823 20240712 09.09.2024 SB2024090950
#VU81865 - Heap-based Buffer Overflow
CVE-2023-38545
CWE-122 High
Available
No
5.1.7.2770 20240520 11.10.2023 SB2023101129
SB2023101135
SB2023101149
and 99 more


Showing elements 121 - 140 out of 353