Known vulnerabilities in QuTS hero - page 9

Software: QuTS hero
Software CPE: cpe:2.3:h:qnap_systems:quts-hero:*:*:*:*:*:*:*:*
Total vulnerabilities: 293
Public exploits: 16
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting QuTS hero QuTS hero is affected by 293 known vulnerabilities: 5 critical, 42 high, 98 medium, 148 low Critical High Medium Low

Vulnerabilities (293)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU90714 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-27124
CWE-78 Medium
No
No
h4.5.4.2626 build 20231225, h5.1.3.2578 build 20231110 03.06.2024 SB2024031110
#VU87317 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-32969
CWE-79 Low
No
No
h5.1.4.2596 build 20231128 11.03.2024 SB2024031103
#VU86371 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-50358
CWE-78 High
No
Exploited
h4.5.4.2626 build 20231225, h5.1.5.2647 build 20240118 13.02.2024 SB2024021313
#VU86370 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-47218
CWE-78 Medium
Available
No
h4.5.4.2626 build 20231225, h5.1.5.2647 build 20240118 13.02.2024 SB2024021313
#VU86087 - Unchecked Return Value
CVE-2023-50359
CWE-252 Low
No
No
h5.1.5.2647 build 20240118 05.02.2024 SB2024020539
#VU86079 - Heap-based Buffer Overflow
CVE-2023-41273
CWE-122 Low
No
No
h5.1.2.2534 build 20230927 05.02.2024 SB2024020531
#VU86078 - Memory corruption
CVE-2023-45037
CWE-119 Low
No
No
h5.1.4.2596 build 20231128 05.02.2024 SB2024020532
#VU86077 - Memory corruption
CVE-2023-45036
CWE-119 Low
No
No
h5.1.4.2596 build 20231128 05.02.2024 SB2024020532
#VU86076 - Memory corruption
CVE-2023-45035
CWE-119 Low
No
No
h5.1.4.2596 build 20231128 05.02.2024 SB2024020532
#VU86075 - Memory corruption
CVE-2023-41292
CWE-119 Low
No
No
h5.1.4.2596 build 20231128 05.02.2024 SB2024020532
#VU86074 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-39297
CWE-78 Medium
No
No
h4.5.4.2626 build 20231225, h5.1.4.2596 build 20231128 05.02.2024 SB2024020533
#VU86072 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-41283
CWE-78 Low
No
No
h5.1.4.2596 build 20231128 05.02.2024 SB2024020534
#VU86071 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-41282
CWE-78 Low
No
No
h5.1.4.2596 build 20231128 05.02.2024 SB2024020534
#VU86070 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-41281
CWE-78 Low
No
No
h5.1.4.2596 build 20231128 05.02.2024 SB2024020534
#VU86065 - Resource exhaustion
CVE-2023-45028
CWE-400 Low
No
No
h5.1.5.2647 build 20240118 05.02.2024 SB2024020536
#VU86064 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-45027
CWE-22 Low
No
No
h5.1.5.2647 build 20240118 05.02.2024 SB2024020536
#VU86063 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-45026
CWE-22 Low
No
No
h5.1.5.2647 build 20240118 05.02.2024 SB2024020536
#VU86061 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-47566
CWE-78 Low
No
No
h5.1.5.2647 build 20240118 05.02.2024 SB2024020537
#VU86060 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-47568
CWE-89 Medium
No
No
h4.5.4.2626 build 20231225, h5.1.5.2647 build 20240118 05.02.2024 SB2024020538
#VU86057 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-47567
CWE-78 Low
No
No
h4.5.4.2626 build 20231225, h5.1.5.2647 build 20240118 05.02.2024 SB2024020538


Showing elements 161 - 180 out of 293