5.3

CVSS4.0

CVE-2024-48867 - QTS, QuTS hero

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data. We have already fixed the vulnerability in the following versio…

πŸ“… Published: Dec. 6, 2024, 4:36 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 2:10 p.m.

2.3

CVSS4.0

CVE-2024-48866 - QTS, QuTS hero

An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to run the system into unexpected state. We have already fixed the vulnerability in the following versi…

πŸ“… Published: Dec. 6, 2024, 4:36 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 2:10 p.m.

7.3

CVSS4.0

CVE-2024-48865 - QTS, QuTS hero

An improper certificate validation vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow attackers with local network access to compromise the security of the system. We have already fixed the vulnerability in the following ve…

πŸ“… Published: Dec. 6, 2024, 4:36 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 2:05 p.m.

5.3

CVSS4.0

CVE-2024-48859 - QTS, QuTS hero

An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 buil…

πŸ“… Published: Dec. 6, 2024, 4:35 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 1:59 p.m.

6.8

CVSS4.0

CVE-2024-50404 - Qsync Central

A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: Qsync Central 4…

πŸ“… Published: Dec. 6, 2024, 4:35 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 9:59 p.m.

9.5

CVSS4.0

CVE-2024-50389 - QuRouter

A SQL injection vulnerability has been reported to affect QuRouter. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later

πŸ“… Published: Dec. 6, 2024, 4:35 p.m. πŸ”„ Last Modified: Sept. 24, 2025, 7:18 p.m.

10

CVSS4.0

CVE-2024-50387 - SMB Service

A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: SMB Service 4.15.002 and later SMB Service h4.1…

πŸ“… Published: Dec. 6, 2024, 4:35 p.m. πŸ”„ Last Modified: Dec. 8, 2025, 6:16 p.m.

9.5

CVSS4.0

CVE-2024-50388 - HBS 3 Hybrid Backup Sync

An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.1.673 and later

πŸ“… Published: Dec. 6, 2024, 4:35 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 7:03 p.m.

8.7

CVSS4.0

CVE-2024-53691 - QTS, QuTS hero

A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following …

πŸ“… Published: Dec. 6, 2024, 4:34 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 2:20 p.m.

9.3

CVSS4.0

CVE-2024-54143 - openwrt/asu allows build artifact poisoning via truncated SHA-256 hash and command injection

openwrt/asu is an image on demand server for OpenWrt based distributions. The request hashing mechanism truncates SHA-256 hashes to only 12 characters. This significantly reduces entropy, making it feasible for an attacker to generate collisions. By exploiting this, a previously built malicious ima…

πŸ“… Published: Dec. 6, 2024, 4:14 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 7596 of 34,919
Β« previous page Β» next page
Filters