This page lists publicly disclosed CVE vulnerabilities affecting qnap nas_proxy_server (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2021-34360 | A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later QuTS hero h5.0.0: Proxy Server 1.4.3 ( 2022/01/18 ) and later QuTScloud c4.5.6: Proxy Server 1.4.2 ( 2021/12/30 ) and later | [email protected] | 5.3 | 0.10% | 2022-05-26 | 2024-11-21 |
| CVE-2021-34361 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later | [email protected] | 5.3 | 0.35% | 2022-02-25 | 2024-11-21 |
| CVE-2021-34359 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later | [email protected] | 6.9 | 0.22% | 2022-02-25 | 2024-11-21 |
| CVE-2017-7639 | QNAP NAS application Proxy Server through version 1.2.0 does not authenticate requests properly. Successful exploitation can lead to change of the settings of Proxy Server. | [email protected] | 5.3 | 0.19% | 2018-06-05 | 2024-11-21 |
| CVE-2017-7637 | QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to run arbitrary OS commands against the system with root privileges. | [email protected] | 9.8 | 3.25% | 2018-06-05 | 2024-11-21 |
| CVE-2017-7636 | Cross-site scripting (XSS) vulnerability in QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to inject arbitrary web script or HTML. | [email protected] | 6.1 | 0.23% | 2018-06-05 | 2024-11-21 |
| CVE-2017-7635 | QNAP NAS application Proxy Server through version 1.2.0 does not utilize CSRF protections. | [email protected] | 8.8 | 0.16% | 2018-06-05 | 2024-11-21 |