qts vulnerabilities
CVEs whose affected-version data names the qts package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2024-38639Medium· 4.8An improper authentication vulnerability has been reported to affect product
An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulnerability to compromise the security of the system. QTS is not affected. We have already fixed the vulnerability…
CVE-2018-19953Medium· 6.1CISA KEV0dayIf exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 202001…
CVE-2018-19949Critical· 9.8CISA KEV0dayIf exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130…
CVE-2018-19943High· 8.0CISA KEV0dayIf exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build …