Qnap
Qnap Music Station: vulnerabilidades y CVE
Qnap Music Station tiene 13 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses0
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-45038 | Alta (8.8) | 1.2% | — | 6 sept 2024 | An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the… |
| CVE-2023-39299 | Alta (7.5) | 0.61% | — | 3 nov 2023 | A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have… |
| CVE-2023-23366 | Media (6.5) | 0.55% | — | 6 oct 2023 | A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the contents of unexpected files and expose sensitive data via a network.… |
| CVE-2023-23365 | Media (6.5) | 0.55% | — | 6 oct 2023 | A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the contents of unexpected files and expose sensitive data via a network.… |
| CVE-2020-36197 | Alta (8.8) | 18% | — | 13 may 2021 | An improper access control vulnerability has been reported to affect earlier versions of Music Station. If exploited, this vulnerability allows attackers to compromise the security of the software by gaining privileges,… |
| CVE-2020-2494 | Media (6.1) | 0.99% | — | 10 dic 2020 | This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in the following versions of Music Station. QuTS hero h4.5.1: Music… |
| CVE-2018-19952 | Alta (7.5) | 1.3% | — | 2 nov 2020 | If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9;… |
| CVE-2018-19951 | Media (6.1) | 0.77% | — | 2 nov 2020 | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9;… |
| CVE-2018-19950 | Crítica (9.8) | 2.1% | — | 2 nov 2020 | If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9;… |
| CVE-2019-7185 | Media (4.8) | 1.5% | — | 5 dic 2019 | This cross-site scripting (XSS) vulnerability in Music Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Music… |
| CVE-2018-0729 | Crítica (9.8) | 2.3% | — | 4 dic 2019 | This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating Music Station to their latest versions. |
| CVE-2018-0718 | Crítica (9.8) | 1.7% | — | 14 sept 2018 | Command injection vulnerability in Music Station 5.1.2 and earlier versions in QNAP QTS 4.3.3 and 4.3.4 could allow remote attackers to run arbitrary commands in the compromised application. |
| CVE-2017-13069 | Crítica (9.8) | 1.7% | — | 6 oct 2017 | QNAP discovered a number of command injection vulnerabilities found in Music Station versions 4.8.6 (for QTS 4.2.x), 5.0.7 (for QTS 4.3.x), and earlier. If exploited, these vulnerabilities may allow a remote attacker to… |