Known vulnerabilities in QuTS hero - page 3

Software: QuTS hero
Software CPE: cpe:2.3:h:qnap_systems:quts-hero:*:*:*:*:*:*:*:*
Total vulnerabilities: 293
Public exploits: 16
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting QuTS hero QuTS hero is affected by 293 known vulnerabilities: 5 critical, 42 high, 98 medium, 148 low Critical High Medium Low

Vulnerabilities (293)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU120949 - Allocation of Resources Without Limits or Throttling
CVE-2025-57705
CWE-770 Low
No
No
h5.2.7.3256 build 20250913, h5.3.1.3250 build 20250912 05.01.2026 SB2026010585
#VU120948 - Allocation of Resources Without Limits or Throttling
CVE-2025-47208
CWE-770 Medium
No
No
h5.2.7.3256 build 20250913, h5.3.1.3250 build 20250912 05.01.2026 SB2026010585
#VU120928 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-59381
CWE-22 Low
No
No
h5.2.8.3321 build 20251117, h5.3.1.3250 build 20250912 05.01.2026 SB2026010582
#VU120927 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-59380
CWE-22 Low
No
No
h5.2.8.3321 build 20251117, h5.3.1.3250 build 20250912 05.01.2026 SB2026010582
#VU120926 - Memory corruption
CVE-2025-62852
CWE-119 Low
No
No
h5.2.8.3321 build 20251117, h5.3.1.3250 build 20250912 05.01.2026 SB2026010582
#VU120923 - Memory corruption
CVE-2025-48721
CWE-119 Low
No
No
h5.2.8.3321 build 20251117, h5.3.1.3250 build 20250912 05.01.2026 SB2026010582
#VU120921 - Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2025-9110
CWE-497 Medium
No
No
h5.2.8.3321 build 20251117, h5.3.1.3250 build 20250912 05.01.2026 SB2026010582
#VU118513 - Improper input validation
CVE-2025-62848
CWE-20 Critical
No
No
h5.2.7.3297 build 20251024, h5.3.1.3292 build 20251024 13.11.2025 SB2025111353
#VU118514 - Improper input validation
CVE-2025-62849
CWE-20 Critical
No
No
h5.2.7.3297 build 20251024, h5.3.1.3292 build 20251024 13.11.2025 SB2025111353
#VU118512 - Improper input validation
CVE-2025-62847
CWE-20 Critical
No
No
h5.2.7.3297 build 20251024, h5.3.1.3292 build 20251024 13.11.2025 SB2025111353
#VU116683 - Use of Externally-Controlled Format String
CVE-2025-53407
CWE-134 Low
No
No
h5.2.6.3195 build 20250715 07.10.2025 SB2025100744
#VU116682 - Use of Externally-Controlled Format String
CVE-2025-53406
CWE-134 Low
No
No
h5.2.6.3195 build 20250715 07.10.2025 SB2025100744
#VU116681 - Use of Externally-Controlled Format String
CVE-2025-52429
CWE-134 Low
No
No
h5.2.6.3195 build 20250715 07.10.2025 SB2025100744
#VU116680 - Use of Externally-Controlled Format String
CVE-2025-48730
CWE-134 Low
No
No
h5.2.6.3195 build 20250715 07.10.2025 SB2025100744
#VU116679 - NULL Pointer Dereference
CVE-2025-52866
CWE-476 Low
No
No
h5.2.6.3195 build 20250715 07.10.2025 SB2025100744
#VU116678 - NULL Pointer Dereference
CVE-2025-52862
CWE-476 Low
No
No
h5.2.6.3195 build 20250715 07.10.2025 SB2025100744
#VU116677 - NULL Pointer Dereference
CVE-2025-52860
CWE-476 Low
No
No
h5.2.6.3195 build 20250715 07.10.2025 SB2025100744
#VU116676 - NULL Pointer Dereference
CVE-2025-52859
CWE-476 Low
No
No
h5.2.6.3195 build 20250715 07.10.2025 SB2025100744
#VU116675 - NULL Pointer Dereference
CVE-2025-52858
CWE-476 Low
No
No
h5.2.6.3195 build 20250715 07.10.2025 SB2025100744
#VU116671 - NULL Pointer Dereference
CVE-2025-52853
CWE-476 Low
No
No
h5.2.6.3195 build 20250715 07.10.2025 SB2025100744


Showing elements 41 - 60 out of 293