ZeroHour

Vulnerabilities

617 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-26239
A buffer overflow vulnerability has been reported to affect File Station 5.

A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5208 and later

NVD description · AI analysis pending
6.3
group max
<1%
  • qnap file station
CVE-2026-26237
A missing authorization vulnerability has been reported to affect QuMagie.

A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the following version: QuMagie 2.9.0 and later

NVD description · AI analysis pending
6.6<1%
  • qnap qumagie
CVE-2025-66276
QuTS hero is not affected.

QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later

NVD description · AI analysis pending
9.2
group max
<1%
  • qnap qts
CVE-2025-62851
A path traversal vulnerability has been reported to affect License Center.

A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: License Center 1.9.56 and later

NVD description · AI analysis pending
4.6<1%
  • qnap license center
CVE-2025-62850
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions.

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3459 build 20260409 and later

NVD description · AI analysis pending
5.1<1%
  • qnap quts hero
CVE-2025-58468
A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center.

A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: Notification Center 1.10.0.3291 and later

NVD description · AI analysis pending
5.1<1%
  • qnap notification center
CVE-2026-44083
+1 in the same advisory: …26236
An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie.

An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to gain unintended privileges. We have already fixed the vulnerability in the following version: QuMagie 2.9.1 and later

NVD description · AI analysis pending
8.7
group max
<1%
  • qnap qumagie
CVE-2026-41539
+1 in the same advisory: …62858
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions.

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.3499 build 20260514 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3500 build 20260520 and later

NVD description · AI analysis pending
6.3
group max
<1%
  • qnap qts
  • qnap quts hero
CVE-2026-22897
+3 in the same advisory: …22900 …22901 …22902
A command injection vulnerability has been reported to affect QuNetSwitch.

A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.4.0415 and later

NVD description · AI analysis pending
8.1
group max
1%
  • qnap qunetswitch
CVE-2026-22898
A missing authentication for critical function vulnerability has been reported to affect QVR Pro.

A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerability to gain access to the system. We have already fixed the vulnerability in the following version: QVR Pro 2.7.4.14 and later

NVD description · AI analysis pending
9.3<1%
  • qnap qvr pro
CVE-2026-22895
A cross-site scripting (XSS) vulnerability has been reported to affect QuFTP Service.

A cross-site scripting (XSS) vulnerability has been reported to affect QuFTP Service. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QuFTP Service 1.4.3 and later QuFTP Service 1.5.2 and later QuFTP Service 1.6.2 and later

NVD description · AI analysis pending
6.2<1%
  • qnap quftp
CVE-2025-62846
+3 in the same advisory: …62845 …62844 …62843
An SQL injection vulnerability has been reported to affect QHora.

An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: QuRouter 2.6.2.007 and later

NVD description · AI analysis pending
7.3
group max
<1%
  • qnap qurouter
CVE-2025-59383
A buffer overflow vulnerability has been reported to affect Media Streaming Add-On.

A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Media Streaming Add-on 500.1.1 and later

NVD description · AI analysis pending
2.7<1%
  • qnap media streaming add-on
CVE-2025-59388
A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector.

A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit the vulnerability to gain unauthorized access. We have already fixed the vulnerability in the following version: Hyper Data Protector 2.3.1.455 and later

NVD description · AI analysis pending
6.6<1%
  • qnap hyper data protector
CVE-2024-14026
A command injection vulnerability has been reported to affect several QNAP operating system versions.

A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.3.3006 build 20250108 and later QuTS hero h5.1.9.2954 build 20241120 and later QuTS hero h5.2.3.3006 build 20250108 and later

NVD description · AI analysis pending
2.0<1%
  • qnap qts
  • qnap quts hero
CVE-2024-14025
+1 in the same advisory: …14024
An SQL injection vulnerability has been reported to affect Video Station.

An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Video Station 5.8.2 and later

NVD description · AI analysis pending
0.1<1%
  • qnap video station
CVE-2025-62853
A path traversal vulnerability has been reported to affect File Station 5.

A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5166 and later

NVD description · AI analysis pending
5.2
group max
<1%
  • qnap file station
CVE-2025-68406
+2 in the same advisory: …58472 …58471
A path traversal vulnerability has been reported to affect Qsync Central.

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

NVD description · AI analysis pending
1.3
group max
<1%
  • qnap qsync central
CVE-2025-66277
A link following vulnerability has been reported to affect several QNAP operating system versions.

A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3350 build 20251216 and later QuTS hero h5.3.2.3354 build 20251225 and later QuTS hero h5.2.8.3350 build 20251216 and later

NVD description · AI analysis pending
9.2<1%
  • qnap qts
  • qnap quts hero
CVE-2025-66274
+1 in the same advisory: …59386
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions.

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.2.3354 build 20251225 and later QuTS hero h6.0.0.3397 build 20260206 and later

NVD description · AI analysis pending
5.1
group max
<1%
  • qnap quts hero