Known vulnerabilities in QuTS hero - page 15

Software: QuTS hero
Software CPE: cpe:2.3:h:qnap_systems:quts-hero:*:*:*:*:*:*:*:*
Total vulnerabilities: 293
Public exploits: 16
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting QuTS hero QuTS hero is affected by 293 known vulnerabilities: 5 critical, 42 high, 98 medium, 148 low Critical High Medium Low

Vulnerabilities (293)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU54489 - Command injection
CVE-2021-28804
CWE-77 High
No
No
h4.5.1.1582 build 20210217 01.07.2021 SB2021070102
#VU54488 - Command injection
CVE-2021-28802
CWE-77 High
No
No
h4.5.1.1582 build 20210217 01.07.2021 SB2021070102
#VU54485 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-36194
CWE-79 Low
No
No
h4.5.2.1638 build 20210414 01.07.2021 SB2021070105
#VU54221 - Unprotected Storage of Credentials
CVE-2021-28815
CWE-256 Medium
No
No
h4.5.2 18.06.2021 SB2021061809
#VU53810 - Command injection
CWE-77 Medium
No
No
h4.5.2: 1.12.1012 04.06.2021 SB2021060404
#VU53763 - Command injection
CVE-2021-28812
CWE-77 High
No
No
h4.5.2 03.06.2021 SB2021060311
#VU53762 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-28807
CWE-79 Low
No
No
h4.5.2 03.06.2021 SB2021060310
#VU53422 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-28798
CWE-22 Medium
No
No
h4.5.2.1638 build 20210414 21.05.2021 SB2021052110
#VU52761 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-28806
CWE-79 Low
No
No
h4.5.2.1638 build 20210414 29.04.2021 SB2021042927
SB2021060313
#VU52748 - Out-of-bounds read
CVE-2021-20254
CWE-125 Medium
No
No
h4.5.3.1670 build 20210515 29.04.2021 SB2021042916
SB2021052619
SB2021060941
and 30 more
#VU49845 - Insufficient Verification of Data Authenticity
CVE-2020-25686
CWE-345 Low
Available
No
h4.5.3.1670 build 20210515 20.01.2021 SB2021012070
SB20210120108
SB20210120122
and 27 more
#VU49844 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2020-25685
CWE-327 Low
Available
No
h4.5.3.1670 build 20210515 20.01.2021 SB2021012070
SB20210120107
SB20210120122
and 27 more
#VU49147 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2020-25847
CWE-78 High
No
No
h4.5.1.1491 build 20201119 24.12.2020 SB2020122405


Showing elements 281 - 300 out of 293