CVE-2018-19953Medium· 6.1▾ Midnight⚠ Exploited in the wild0dayIf exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 202001…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 33.6 · likelihood 4.8 · exploitation 25 · ransomware 5
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Jun 14, 2022
Last analysed / modified upstream
24%
Added to the CISA catalog on May 24, 2022. Federal remediation due Jun 14, 2022. View catalog ↗
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.
qts < 4.2.6qts >= 4.3.1.0013, < 4.3.3.1161qts >= 4.3.4, < 4.3.4.1190qts >= 4.3.6, < 4.3.6.1218qts >= 4.4.0, < 4.4.1.1201qts >= 4.4.2, < 4.4.2.1231qts = 4.2.6Upgrade past the affected range:
qts 4.4.2.1231Connected by shared product, vendor, weakness, or advisory.
CVE-2018-19943High· 8.0If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code
CVE-2018-19949Critical· 9.8If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands
CVE-2020-3580Medium· 6.1Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting …
CVE-2018-6882Medium· 6.1Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTM…
CVE-2024-38639Medium· 4.8An improper authentication vulnerability has been reported to affect product
CVE-2021-41164High· 8.2CKEditor4 is an open source WYSIWYG HTML editor