1.3

CVSS4.0

CVE-2025-52864 - QTS, QuTS hero

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3…

πŸ“… Published: Jan. 2, 2026, 2:54 p.m. πŸ”„ Last Modified: Jan. 5, 2026, 8:13 p.m.

1.3

CVSS4.0

CVE-2025-52863 - QTS, QuTS hero

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3…

πŸ“… Published: Jan. 2, 2026, 2:53 p.m. πŸ”„ Last Modified: Jan. 5, 2026, 8:13 p.m.

1.2

CVSS4.0

CVE-2025-52431 - QTS, QuTS hero

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the follo…

πŸ“… Published: Jan. 2, 2026, 2:53 p.m. πŸ”„ Last Modified: Jan. 5, 2026, 8:21 p.m.

1.2

CVSS4.0

CVE-2025-52430 - QTS, QuTS hero

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the follo…

πŸ“… Published: Jan. 2, 2026, 2:53 p.m. πŸ”„ Last Modified: Jan. 5, 2026, 8:22 p.m.

1.2

CVSS4.0

CVE-2025-52426 - QTS, QuTS hero

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the follo…

πŸ“… Published: Jan. 2, 2026, 2:53 p.m. πŸ”„ Last Modified: Jan. 5, 2026, 8:22 p.m.

4.9

CVSS4.0

CVE-2025-47208 - QTS, QuTS hero

An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same t…

πŸ“… Published: Jan. 2, 2026, 2:52 p.m. πŸ”„ Last Modified: Jan. 5, 2026, 7:47 p.m.

1.3

CVSS4.0

CVE-2025-44013 - QTS, QuTS hero

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versi…

πŸ“… Published: Jan. 2, 2026, 2:52 p.m. πŸ”„ Last Modified: Jan. 5, 2026, 8:22 p.m.

2.2

CVSS4.0

CVE-2025-62857 - QuMagie

A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following version: QuMagie 2.8.1 and later

πŸ“… Published: Jan. 2, 2026, 2:51 p.m. πŸ”„ Last Modified: Jan. 5, 2026, 8:39 p.m.

5.1

CVSS4.0

CVE-2025-15438 - PluXml Media Management medias.php __destruct deserialization

A vulnerability was determined in PluXml up to 5.8.22. Affected is the function FileCookieJar::__destruct of the file core/admin/medias.php of the component Media Management Module. Executing a manipulation of the argument File can lead to deserialization. The attack can be launched remotely. The e…

πŸ“… Published: Jan. 2, 2026, 2:32 p.m. πŸ”„ Last Modified: Feb. 27, 2026, 3:45 a.m.

6.9

CVSS4.0

CVE-2026-0565 - code-projects Content Management System delete.php sql injection

A weakness has been identified in code-projects Content Management System 1.0. This issue affects some unknown processing of the file /admin/delete.php. Executing a manipulation of the argument del can lead to sql injection. The attack can be executed remotely. The exploit has been made available t…

πŸ“… Published: Jan. 2, 2026, 2:02 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 9:16 a.m.
Total resulsts: 343996
Page 1789 of 34,400
Β« previous page Β» next page
Filters