Known vulnerabilities in QVR
Vendor:
QNAP Systems, Inc.
Software:
QVR
Software CPE:
cpe:2.3:a:qnap_systems:qvr:*:*:*:*:*:*:*:*
Website:
https://www.qnap.com
Total vulnerabilities:
13
Public exploits:
0
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (13)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU114662 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-52861 |
CWE-22 | Low | 5.1.6 20250621 | 02.09.2025 |
SB2025090235 |
||
| #VU114661 - Improper Authentication CVE-2025-52856 |
CWE-287 | High | 5.1.6 20250621 | 02.09.2025 |
SB2025090235 |
||
| #VU84036 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2023-47565 |
CWE-78 | High | 5.0.0 | 11.12.2023 |
SB2023121112 |
||
| #VU74200 - Command injection CVE-2023-23355 |
CWE-77 | Medium | - | 30.03.2023 |
SB2023033031 |
||
| #VU68701 - Heap-based Buffer Overflow CVE-2022-3437 |
CWE-122 | Low | - | 25.10.2022 |
SB2022102524 SB2022102558 SB2022102521 and 33 more |
||
| #VU68700 - UNIX Symbolic Link (Symlink) Following CVE-2022-3592 |
CWE-61 | Medium | - | 25.10.2022 |
SB2022102524 SB2023033037 SB2023091702 and 4 more |
||
| #VU62836 - Command injection CVE-2022-27588 |
CWE-77 | High | 5.1.6 20220401 | 06.05.2022 |
SB2022050603 |
||
| #VU58396 - Improper Authentication CVE-2021-38686 |
CWE-287 | Medium | 5.1.6 20211109 | 29.11.2021 |
SB2021112901 |
||
| #VU58395 - Command injection CVE-2021-38685 |
CWE-77 | High | 5.1.6 20211109 | 29.11.2021 |
SB2021112901 |
||
| #VU56997 - Command injection CVE-2021-34352 |
CWE-77 | High | 5.1.5 20210902 | 01.10.2021 |
SB2021100108 |
||
| #VU56879 - Command injection CVE-2021-34351 |
CWE-77 | High | 5.1.5 20210803 | 27.09.2021 |
SB2021092701 |
||
| #VU56878 - Command injection CVE-2021-34349 |
CWE-77 | High | 5.1.5 20210803 | 27.09.2021 |
SB2021092701 |
||
| #VU56877 - Command injection CVE-2021-34348 |
CWE-77 | High | 5.1.5 20210803 | 27.09.2021 |
SB2021092701 |