Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Qnap Subscribe
Filtered by product Qes
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-2499 1 Qnap 1 Qes 2020-12-28 4.0 MEDIUM 7.2 HIGH
A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded password. QNAP has already fixed the issue in QES 2.1.1 Build 20200515 and later.
CVE-2020-2503 1 Qnap 1 Qes 2020-12-28 3.5 LOW 5.4 MEDIUM
If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
CVE-2020-2504 1 Qnap 1 Qes 2020-12-28 5.0 MEDIUM 7.5 HIGH
If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
CVE-2020-2505 1 Qnap 1 Qes 2020-12-28 2.1 LOW 2.3 LOW
If exploited, this vulnerability could allow attackers to gain sensitive information via generation of error messages. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.