Known vulnerabilities in QuTS hero h4.5.0.1279 build 20200421

Software: QuTS hero
Version: h4.5.0.1279 build 20200421
Software CPE: cpe:2.3:h:qnap_systems:quts-hero:*:*:*:*:*:*:*:*
Total vulnerabilities: 29
Public exploits: 6
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting QuTS hero version h4.5.0.1279 build 20200421 QuTS hero h4.5.0.1279 build 20200421 is affected by 29 vulnerabilities: 1 critical, 10 high, 13 medium, 5 low Critical High Medium Low

Vulnerabilities (29)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU130763 - Resource Management Errors
CVE-2026-43284
CWE-399 High
Public exploit available
Exploited
- 08.05.2026 SB20260508111
SB20260508120
SB20260508121
and 72 more
#VU130759 - Resource Management Errors
CVE-2026-43500
CWE-399 High
Public exploit available
Exploited
- 08.05.2026 SB20260508108
SB20260508120
SB20260508121
and 32 more
#VU93513 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2024-6387
CWE-362 High
Public exploit available
No
- 01.07.2024 SB2024070144
SB2024070145
SB2024070152
and 89 more
#VU86371 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-50358
CWE-78 High
No
Exploited
h4.5.4.2626 build 20231225, h5.1.5.2647 build 20240118 13.02.2024 SB2024021313
#VU86370 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-47218
CWE-78 Medium
Public exploit available
No
h4.5.4.2626 build 20231225, h5.1.5.2647 build 20240118 13.02.2024 SB2024021313
#VU65827 - Use After Free
CVE-2022-32746
CWE-416 Low
No
No
h4.5.4.2138 build 20220824, h5.0.0.2131 build 20220815 27.07.2022 SB2022072721
SB2022072728
SB2022072922
and 30 more
#VU65826 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-32745
CWE-835 Medium
No
No
h4.5.4.2138 build 20220824, h5.0.0.2131 build 20220815 27.07.2022 SB2022072721
SB2022072728
SB2022072922
and 19 more
#VU65825 - Permissions, Privileges, and Access Controls
CVE-2022-32744
CWE-264 Low
No
No
h4.5.4.2138 build 20220824, h5.0.0.2131 build 20220815 27.07.2022 SB2022072721
SB2022072728
SB2022072922
and 20 more
#VU65824 - Missing release of memory after effective lifetime
CVE-2022-32742
CWE-401 Low
No
No
h4.5.4.2138 build 20220824, h5.0.0.2131 build 20220815 27.07.2022 SB2022072721
SB2022072728
SB2022072922
and 36 more
#VU65820 - Permissions, Privileges, and Access Controls
CVE-2022-2031
CWE-264 Medium
No
No
h4.5.4.2138 build 20220824, h5.0.0.2131 build 20220815 27.07.2022 SB2022072721
SB2022072728
SB2022072922
and 15 more
#VU64089 - Improper Authentication
CVE-2022-31813
CWE-287 Medium
No
No
- 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 49 more
#VU64088 - Out-of-bounds read
CVE-2022-30556
CWE-125 Medium
No
No
- 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 31 more
#VU64086 - Resource exhaustion
CVE-2022-30522
CWE-400 Medium
No
No
- 08.06.2022 SB2022060817
SB2022060901
SB2022061723
and 31 more
#VU64085 - Improper input validation
CVE-2022-29404
CWE-20 Medium
No
No
- 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 30 more
#VU64083 - Out-of-bounds read
CVE-2022-28615
CWE-125 Low
No
No
- 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 41 more
#VU64081 - Out-of-bounds read
CVE-2022-28614
CWE-125 Low
No
No
- 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 36 more
#VU64080 - Out-of-bounds read
CVE-2022-28330
CWE-125 Medium
No
No
- 08.06.2022 SB2022060817
SB2022060901
SB2022070730
and 11 more
#VU64078 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-26377
CWE-444 Medium
Public exploit available
No
- 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 39 more
#VU61620 - Improper Handling of Exceptional Conditions
CVE-2022-23121
CWE-755 High
No
No
- 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 7 more
#VU22304 - Memory corruption
CVE-2019-11043
CWE-119 High
Public exploit available
Exploited
h5.0.0.2069 Build 20220614 27.10.2019 SB2019102707
SB2019102708
SB2019102709
and 22 more


Showing elements 1 - 20 out of 29