logo
Karzemrok

Vulnerability disclosure

  • Home
  • Disclosure list
  • Whoami
Drapeau Français

© 2024. All rights reserved.

  • QNAP QSA-24-36 : Notes Station 3 - Multiple vulnerabilities leading to full system compromise - CVE-2024-38643, CVE-2024-38644, CVE-2024-38645, CVE-2024-38646
  • QNAP QSA-24-40 : QNAP AI Core - Docker Image leaking GitHub Personal Access Token - CVE-2024-38647
  • QNAP QSA-24-20 : License Center - Authenticated remote code execution - CVE-2024-21903
  • QNAP QSA-24-25 : Music Station - Unauthenticated file read and authentication bypass - CVE-2023-45038
  • QNAP QSA-22-14 : VideoStation - Multiple Vulnerabilities
  • QNAP QSA-22-15 : PhotoStation - Application Privileges Checking Bypass
  • QNAP QSA-21-25 : Helpdesk - A simple user without privileges can gain administrative access on the NAS
  • Synology SA-20:25 : SafeAccess - Multiple Vulnerabilities
  • CVE-2020-25867 : SoPlanning Sharing Key Bypass
  • Synology SA-18-15 : Photo Station - Privilege Escalation and CRLF
  • Synology SA-17:17 : Surveillance Station - Path Traversal