5.1

CVSS4.0

CVE-2024-50405 - QTS, QuTS hero

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify application data. We have already fixed the โ€ฆ

๐Ÿ“… Published: March 7, 2025, 4:13 p.m. ๐Ÿ”„ Last Modified: Sept. 20, 2025, 3:27 a.m.

7.7

CVSS4.0

CVE-2024-50394 - Helpdesk

An improper certificate validation vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: Helpdesk 3.3.3 and later

๐Ÿ“… Published: March 7, 2025, 4:13 p.m. ๐Ÿ”„ Last Modified: Jan. 22, 2026, 6:30 p.m.

7.7

CVSS4.0

CVE-2024-50390 - QHora

A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later

๐Ÿ“… Published: March 7, 2025, 4:13 p.m. ๐Ÿ”„ Last Modified: Sept. 24, 2025, 8:32 p.m.

5.3

CVSS4.0

CVE-2024-48864 - File Station 5

A files or directories accessible to external parties vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers to read/write files or directories. We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4โ€ฆ

๐Ÿ“… Published: March 7, 2025, 4:12 p.m. ๐Ÿ”„ Last Modified: Sept. 19, 2025, 5:19 p.m.

2.1

CVSS4.0

CVE-2024-38638 - QTS, QuTS hero

An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. QTS 5.2.x/QuTS hero h5.2.x are not affected. We have already fixeโ€ฆ

๐Ÿ“… Published: March 7, 2025, 4:12 p.m. ๐Ÿ”„ Last Modified: Sept. 23, 2025, 2:22 p.m.

5.3

CVSS3.1

CVE-2024-13086 - QTS, QuTS hero

An exposure of sensitive information vulnerability has been reported to affect product. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: QTS 5.2.0.2851 build 20240808 and later Qโ€ฆ

๐Ÿ“… Published: March 7, 2025, 4:12 p.m. ๐Ÿ”„ Last Modified: Jan. 30, 2026, 6:54 p.m.

7.5

CVSS3.1

CVE-2025-27604 - XWiki Confluence Migrator Pro's homepage is public

XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. The homepage of the application is public which enables a guest to download the package which might contain sensitive information. This vulnerability is fixed in 1.11.7.

๐Ÿ“… Published: March 7, 2025, 4:11 p.m. ๐Ÿ”„ Last Modified: March 13, 2025, 2:40 p.m.

9.1

CVSS3.1

CVE-2025-27603 - XWiki Confluence Migrator Pro allows Remote Code Execution via unescaped translations

XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. A user that doesn't have programming rights can execute arbitrary code due to an unescaped translation when creating a page using the Migration Page template. This vulnerability is fixed in 1.2.0.

๐Ÿ“… Published: March 7, 2025, 4:06 p.m. ๐Ÿ”„ Last Modified: March 7, 2025, 6:15 p.m.

8.9

CVSS4.0

CVE-2025-27597 - Vue I18n Prototype Pollution in `handleFlatJson`

Vue I18n is the internationalization plugin for Vue.js. @intlify/message-resolver and @intlify/vue-i18n-core are vulnerable to Prototype Pollution through the entry function: handleFlatJson. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the gโ€ฆ

๐Ÿ“… Published: March 7, 2025, 3:51 p.m. ๐Ÿ”„ Last Modified: July 12, 2025, 3:26 p.m.

6.9

CVSS4.0

CVE-2025-27518 - Cognita CORS misconfiguration in backend API server

Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for production by TrueFoundry. An insecure CORS configuration in the Cognita backend server allows arbitrary websites to send cross site requests to the application. This vulnerability is fixeโ€ฆ

๐Ÿ“… Published: March 7, 2025, 3:36 p.m. ๐Ÿ”„ Last Modified: March 7, 2025, 9:49 p.m.
Total resulsts: 343924
Page 5891 of 34,393
ยซ previous page ยป next page
Filters