CVE-2018-19943High· 8.0▾ Abyssal⚠ Exploited in the wild0dayIf exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build …
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 44 · likelihood 3.5 · exploitation 25 · ransomware 5
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Jun 14, 2022
Last analysed / modified upstream
18%
Added to the CISA catalog on May 24, 2022. Federal remediation due Jun 14, 2022. View catalog ↗
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later
qts < 4.2.6qts >= 4.3.1.0013, < 4.3.3.1252qts >= 4.3.4, < 4.3.4.1282qts >= 4.3.6, < 4.3.6.1263qts >= 4.4.0, < 4.4.1.1261qts >= 4.4.2, < 4.4.2.1270qts = 4.2.6Upgrade past the affected range:
qts 4.4.2.1270Connected by shared product, vendor, weakness, or advisory.
CVE-2018-19953Medium· 6.1If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code
CVE-2018-19949Critical· 9.8If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands
CVE-2020-3580Medium· 6.1Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting …
CVE-2018-6882Medium· 6.1Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTM…
CVE-2024-38639Medium· 4.8An improper authentication vulnerability has been reported to affect product
CVE-2021-41164High· 8.2CKEditor4 is an open source WYSIWYG HTML editor