Total CVEs

138,210

Critical Severity

3,547

High Severity

12,695

Last 7 Days

1,870
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,421 - 2,440 of 34,615 CVEs
CVE-2026-24719 HIGH - 7.2

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5....

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Jun 10, 2026
Source: NVD
CVE-2026-24717 MEDIUM - 6.5

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the fol...

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Jun 10, 2026
Source: NVD
CVE-2026-24716 HIGH - 7.2

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the follow...

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Jun 10, 2026
Source: NVD
CVE-2026-22899 MEDIUM - 6.5

A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6....

Vendor: QNAP Systems Inc.
Product: File Station 5
Published: Jun 10, 2026
Source: NVD
CVE-2026-22893 HIGH - 7.2

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5....

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Jun 10, 2026
Source: NVD
CVE-2025-66281 HIGH - 7.2

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20...

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Jun 10, 2026
Source: NVD
CVE-2025-66280 HIGH - 7.2

An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the f...

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Jun 10, 2026
Source: NVD
CVE-2025-66279 HIGH - 7.2

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5....

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Jun 10, 2026
Source: NVD
CVE-2025-66273 HIGH - 7.2

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5....

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Jun 10, 2026
Source: NVD
CVE-2025-62851 MEDIUM - 4.4

A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: License C...

Vendor: QNAP Systems Inc.
Product: License Center
Published: Jun 10, 2026
Source: NVD
CVE-2025-62850 HIGH - 7.2

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the follow...

Vendor: QNAP Systems Inc.
Product: QuTS hero
Published: Jun 10, 2026
Source: NVD
CVE-2025-66276 CRITICAL - 9.8

QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Jun 10, 2026
Source: NVD

QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero, QuTScloud
Published: Jun 10, 2026
Source: NVD

A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: Notification Center 1.10.0.3291 ...

Vendor: QNAP Systems Inc.
Product: Notification Center
Published: Jun 10, 2026
Source: NVD
CVE-2026-46532 MEDIUM - 4.6

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0, an out-of-bounds read exists in the BlueDroid AVRCP vendor-command parser (avrc_pars_vendor_cmd() in components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c). This issue has been ...

Vendor: espressif
Product: esp-idf
Published: Jun 10, 2026
Source: NVD
CVE-2026-45542 HIGH - 7.1

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a heap buffer overflow exists in the Security Scheme 2 (SRP6a) session-setup path of the protocomm component. The first-phase handler (handle_session_command0() in components/pro...

Vendor: espressif
Product: esp-idf
Published: Jun 10, 2026
Source: NVD
CVE-2026-45541 HIGH - 7.5

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a NULL-pointer dereference exists in the WebSocket subprotocol-negotiation path of the esp_http_server component. While parsing the client-supplied Sec-WebSocket-Protocol request...

Vendor: espressif
Product: esp-idf
Published: Jun 10, 2026
Source: NVD
CVE-2026-45329 HIGH - 7.1

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c validated only some of the caller-supplied pointer arguments, leaving input pointer arguments unchecked....

Vendor: espressif
Product: esp-idf
Published: Jun 10, 2026
Source: NVD
CVE-2026-45328 CRITICAL - 9.3

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c that bridge calls from the user application (i.e. the REE) to TEE-protected hardware perip...

Vendor: espressif
Product: esp-idf
Published: Jun 10, 2026
Source: NVD
CVE-2026-45160 MEDIUM - 6.5

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0.1, an out-of-bounds read flaw exists in the DHCP server option parser (parse_options() in components/lwip/apps/dhcpserver/dhcpserver.c) shipped with ESP-IDF's lwIP component....

Vendor: espressif
Product: esp-idf
Published: Jun 10, 2026
Source: NVD