Show filters
203 Total Results
Displaying 131-140 of 203
Sort by:
Attacker Value
Unknown

CVE-2022-27597

Disclosure Date: March 27, 2023 (last updated February 24, 2025)
A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret values. The vulnerability affects the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances) We have already fixed the vulnerability in the following versions: QTS 5.0.1.2346 build 20230322 and later QuTS hero h5.0.1.2348 build 20230324 and later
Attacker Value
Unknown

CVE-2022-27596

Disclosure Date: January 30, 2023 (last updated February 24, 2025)
A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QuTS hero, QTS: QuTS hero h5.0.1.2248 build 20221215 and later QTS 5.0.1.2234 build 20221201 and later
Attacker Value
Unknown

CVE-2023-22626

Disclosure Date: January 05, 2023 (last updated February 24, 2025)
PgHero before 3.1.0 allows Information Disclosure via EXPLAIN because query results may be present in an error message. (Depending on database user privileges, this may only be information from the database, or may be information from file contents on the database server.)
Attacker Value
Unknown

CVE-2022-41648

Disclosure Date: October 25, 2022 (last updated February 24, 2025)
The HEIDENHAIN Controller TNC 640, version 340590 07 SP5, running HEROS 5.08.3 controlling the HARTFORD 5A-65E CNC machine is vulnerable to improper authentication, which may allow an attacker to deny service to the production line, steal sensitive data from the production line, and alter any products created by the production line.
Attacker Value
Unknown

CVE-2021-42010

Disclosure Date: October 24, 2022 (last updated February 24, 2025)
Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-incubating which addresses this issue.
Attacker Value
Unknown

CVE-2022-3074

Disclosure Date: September 26, 2022 (last updated February 24, 2025)
The Slider Hero WordPress plugin before 8.4.4 does not escape the slider Name, which could allow high-privileged users to perform Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2020-28437

Disclosure Date: August 02, 2022 (last updated February 24, 2025)
This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js.
Attacker Value
Unknown

CVE-2022-0885

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments.
Attacker Value
Unknown

CVE-2021-44051

Disclosure Date: May 06, 2022 (last updated February 23, 2025)
A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero and QTS: QuTScloud c5.0.1.1949 and later QuTS hero h5.0.0.1986 build 20220324 and later QTS 5.0.0.1986 build 20220324 and later
Attacker Value
Unknown

CVE-2021-38693

Disclosure Date: May 06, 2022 (last updated February 23, 2025)
A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Appliance. If exploited, this vulnerability allows attackers to read the contents of unexpected files and expose sensitive data. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero, QTS, QVR Pro Appliance: QuTScloud c5.0.1.1949 and later QuTS hero h5.0.0.1949 build 20220215 and later QuTS hero h4.5.4.1951 build 20220218 and later QTS 5.0.0.1986 build 20220324 and later QTS 4.5.4.1991 build 20220329 and later