|
1701
|
9.8 |
CRITICAL
Network
|
qnap
|
qvr_pro
|
A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerability to gain access to the system.
We have alread…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-22898
|
2026-04-14 23:33 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1702
|
9.8 |
CRITICAL
Network
|
qnap
|
qvr_pro
|
Se ha reportado una vulnerabilidad de autenticación ausente para función crítica que afecta a QVR Pro. Los atacantes remotos pueden entonces explotar la vulnerabilidad para obtener acceso al sistema.…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-22898
|
2026-04-14 23:33 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1703
|
6.7 |
MEDIUM
Local
|
qnap
|
qurouter
|
An improper neutralization of escape, meta, or control sequences vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnera…
|
CWE-150
Improper Neutralization of Escape, Meta, or Control Sequences
|
CVE-2025-62845
|
2026-04-14 23:25 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1704
|
6.7 |
MEDIUM
Local
|
qnap
|
qurouter
|
Una vulnerabilidad de neutralización incorrecta de secuencias de escape, meta o control se ha reportado que afecta a QHora. Si un atacante local obtiene una cuenta de administrador, puede entonces ex…
|
CWE-150
Improper Neutralization of Escape, Meta, or Control Sequences
|
CVE-2025-62845
|
2026-04-14 23:25 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1705
|
5.5 |
MEDIUM
Local
|
qnap
|
qurouter
|
A weak authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to gain sensitive information.
We have alrea…
|
CWE-1390
Weak Authentication
|
CVE-2025-62844
|
2026-04-14 23:24 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1706
|
5.5 |
MEDIUM
Local
|
qnap
|
qurouter
|
Se ha reportado una vulnerabilidad de autenticación débil que afecta a QHora. Si un atacante obtiene acceso a la red local, puede entonces explotar la vulnerabilidad para obtener información sensible…
|
CWE-1390
Weak Authentication
|
CVE-2025-62844
|
2026-04-14 23:24 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1707
|
9.8 |
CRITICAL
Network
|
fortinet
|
forticlientems
|
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized co…
|
CWE-89
SQL Injection
|
CVE-2026-21643
|
2026-04-14 23:21 |
2026-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1708
|
9.8 |
CRITICAL
Network
|
fortinet
|
forticlientems
|
Una vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ('inyección SQL') en Fortinet FortiClientEMS 7.4.4 podría permitir a un atacante no autenticado ej…
|
CWE-89
SQL Injection
|
CVE-2026-21643
|
2026-04-14 23:21 |
2026-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1709
|
6.8 |
MEDIUM
Physics
|
qnap
|
qurouter
|
An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. If an attacker gains physical access, they can then exploit the vulnerability t…
|
CWE-923
Improper Restriction of Communication Channel to Intended Endpoints
|
CVE-2025-62843
|
2026-04-14 23:19 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1710
|
6.8 |
MEDIUM
Physics
|
qnap
|
qurouter
|
Se ha informado de una vulnerabilidad de restricción inadecuada del canal de comunicación a los puntos finales previstos que afecta a QHora. Si un atacante obtiene acceso físico, puede entonces explo…
|
CWE-923
Improper Restriction of Communication Channel to Intended Endpoints
|
CVE-2025-62843
|
2026-04-14 23:19 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|