CVE-2018-19949Critical· 9.8▾ Hadal⚠ Exploited in the wild0dayIf exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130…
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 53.9 · likelihood 4.9 · exploitation 25 · ransomware 5
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Jun 14, 2022
Last analysed / modified upstream
24%
Added to the CISA catalog on May 24, 2022. Federal remediation due Jun 14, 2022. View catalog ↗
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.
qts < 4.2.6qts >= 4.3.1.0013, < 4.3.3.1161qts >= 4.3.4, < 4.3.4.1190qts >= 4.3.6, < 4.3.6.1218qts >= 4.4.0, < 4.4.1.1201qts >= 4.4.2, < 4.4.2.1231qts = 4.2.6Upgrade past the affected range:
qts 4.4.2.1231Connected by shared product, vendor, weakness, or advisory.
CVE-2018-19953Medium· 6.1If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code
CVE-2018-19943High· 8.0If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code
CVE-2022-29499Critical· 9.8The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation
CVE-2015-2291High· 7.8(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted …
CVE-2025-34161High· 8.8Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow
CVE-2024-38639Medium· 4.8An improper authentication vulnerability has been reported to affect product