Qnap
Qnap Media Streaming Add-on: vulnerabilidades y CVE
Qnap Media Streaming Add-on tiene 13 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses3
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-59383 | Baja (2.7) | 0.32% | — | 20 mar 2026 | A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in… |
| CVE-2024-56808 | Baja (2) | 0.60% | — | 11 feb 2026 | A command injection vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute… |
| CVE-2024-56807 | Baja (1.7) | 0.11% | — | 11 feb 2026 | An out-of-bounds read vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network access, they can then exploit the vulnerability to obtain secret data. We have already fixed the… |
| CVE-2024-50395 | Media (6.9) | 1.4% | — | 22 nov 2024 | An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege. We have… |
| CVE-2023-47220 | Media (6.6) | 1.2% | — | 3 may 2024 | An OS command injection vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed… |
| CVE-2023-47222 | Crítica (9.8) | 0.54% | — | 26 abr 2024 | An exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have… |
| CVE-2023-23369 | Crítica (9.8) | 15% | — | 3 nov 2023 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the… |
| CVE-2021-34362 | Alta (7.2) | 1.3% | — | 22 oct 2021 | A command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited, this vulnerability allow remote attackers to run arbitrary commands. We have already fixed this… |
| CVE-2020-36195 | Crítica (9.8) | 1.8% | — | 17 abr 2021 | An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information.… |
| CVE-2017-7641 | Alta (8.8) | 0.45% | — | 8 mar 2018 | QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not utilize CSRF protections. |
| CVE-2017-7640 | Crítica (9.8) | 3.1% | — | 8 mar 2018 | QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the system with root privileges. |
| CVE-2017-7638 | Media (6.5) | 0.67% | — | 8 mar 2018 | QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of… |
| CVE-2017-7634 | Media (6.1) | 0.76% | — | 8 mar 2018 | Cross-site scripting (XSS) vulnerability in QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to inject arbitrary web script or HTML. The injected code will… |