CVE Feed

    Dashboard / CVE

    1.3
    Low

    CVE-2025-54147

    Last Modified: 12 Feb 2026

    A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    1.3
    Low

    CVE-2025-54148

    Last Modified: 12 Feb 2026

    A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    4.9
    Medium

    CVE-2025-54149

    Last Modified: 12 Feb 2026

    An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    4.9
    Medium

    CVE-2025-54150

    Last Modified: 12 Feb 2026

    An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    4.9
    Medium

    CVE-2025-54151

    Last Modified: 12 Feb 2026

    An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    1.3
    Low

    CVE-2025-54152

    Last Modified: 12 Feb 2026

    A use of out-of-range pointer offset vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read sensitive portions of memory. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    3.6
    Low

    CVE-2025-54155

    Last Modified: 12 Feb 2026

    An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5018 and later

    Published: 11 Feb 2026
    3.6
    Low

    CVE-2025-54161

    Last Modified: 12 Feb 2026

    An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5068 and later

    Published: 11 Feb 2026
    4.8
    Medium

    CVE-2025-54162

    Last Modified: 12 Feb 2026

    A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5068 and later

    Published: 11 Feb 2026
    1.2
    Low

    CVE-2025-54163

    Last Modified: 12 Feb 2026

    A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5166 and later

    Published: 11 Feb 2026
    4.9
    Medium

    CVE-2025-54169

    Last Modified: 12 Feb 2026

    An out-of-bounds read vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5068 and later

    Published: 11 Feb 2026
    4.9
    Medium

    CVE-2025-54170

    Last Modified: 12 Feb 2026

    An out-of-bounds read vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    1.1
    Low

    CVE-2025-57707

    Last Modified: 12 Feb 2026

    An improper neutralization of directives in statically saved code ('Static Code Injection') vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to access restricted data / files. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5166 and later

    Published: 11 Feb 2026
    2.3
    Low

    CVE-2025-57708

    Last Modified: 12 Feb 2026

    An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    1.3
    Low

    CVE-2025-57709

    Last Modified: 12 Feb 2026

    A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    3.6
    Low

    CVE-2025-57710

    Last Modified: 12 Feb 2026

    An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    3.6
    Low

    CVE-2025-57711

    Last Modified: 12 Feb 2026

    An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    1.3
    Low

    CVE-2025-57713

    Last Modified: 12 Feb 2026

    A weak authentication vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to gain sensitive information. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5166 and later

    Published: 11 Feb 2026
    1.2
    Low

    CVE-2025-58466

    Last Modified: 12 Feb 2026

    A use of uninitialized variable vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to denial of service conditions, or modify control flow in unexpected ways. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3332 build 20251128 and later QuTS hero h5.2.8.3321 build 20251117 and later

    Published: 11 Feb 2026
    1.3
    Low

    CVE-2025-58467

    Last Modified: 12 Feb 2026

    A relative path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    1.3
    Low

    CVE-2025-58470

    Last Modified: 12 Feb 2026

    A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    1.2
    Low

    CVE-2025-58471

    Last Modified: 12 Feb 2026

    An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following version: Qsync Central 5.2.0.1 ( 2025/12/21 ) and later

    Published: 11 Feb 2026
    1.2
    Low

    CVE-2025-58472

    Last Modified: 12 Feb 2026

    A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    1.2
    Low

    CVE-2025-59386

    Last Modified: 27 Feb 2026

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: QuTS hero h5.3.2.3354 build 20251225 and later

    Published: 11 Feb 2026
    5.2
    Medium

    CVE-2025-62853

    Last Modified: 12 Feb 2026

    A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5166 and later

    Published: 11 Feb 2026
    1.3
    Low

    CVE-2025-62854

    Last Modified: 12 Feb 2026

    An uncontrolled resource consumption vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and later

    Published: 11 Feb 2026
    1.3
    Low

    CVE-2025-62855

    Last Modified: 12 Feb 2026

    A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and later

    Published: 11 Feb 2026
    1.3
    Low

    CVE-2025-62856

    Last Modified: 12 Feb 2026

    A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and later

    Published: 11 Feb 2026
    5.1
    Medium

    CVE-2025-66274

    Last Modified: 9 Jun 2026

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.2.3354 build 20251225 and later QuTS hero h6.0.0.3397 build 20260206 and later

    Published: 11 Feb 2026
    9.2
    Critical

    CVE-2025-66277

    Last Modified: 26 Feb 2026

    A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3350 build 20251216 and later QuTS hero h5.3.2.3354 build 20251225 and later QuTS hero h5.2.8.3350 build 20251216 and later

    Published: 11 Feb 2026
    1.3
    Low

    CVE-2025-66278

    Last Modified: 12 Feb 2026

    A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and later

    Published: 11 Feb 2026
    1.3
    Low

    CVE-2025-68406

    Last Modified: 12 Feb 2026

    A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    1.3
    Low

    CVE-2026-22894

    Last Modified: 17 Apr 2026

    A path traversal vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and later

    Published: 11 Feb 2026
    8.3
    High

    CVE-2025-10174

    Last Modified: 5 Jun 2026

    Cleartext Transmission of Sensitive Information vulnerability in Pan Software & Information Technologies Ltd. PanCafe Pro allows Flooding. This issue affects PanCafe Pro: from < 3.3.2 through 23092025.

    Published: 11 Feb 2026
    8
    High

    CVE-2025-7659

    Last Modified: 26 Feb 2026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to steal tokens and access private repositories by abusing incomplete validation in the Web IDE.

    Published: 11 Feb 2026
    7.5
    High

    CVE-2025-8099

    Last Modified: 13 Feb 2026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.8 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries.

    Published: 11 Feb 2026
    4.3
    Medium

    CVE-2025-12073

    Last Modified: 13 Feb 2026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an authenticated user to perform server-side request forgery against internal services by bypassing protections in the Git repository import functionality.

    Published: 11 Feb 2026
    5.4
    Medium

    CVE-2025-12575

    Last Modified: 13 Feb 2026

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user with certain permissions to make unauthorized requests to internal network services through the GitLab server.

    Published: 11 Feb 2026
    7.3
    High

    CVE-2025-14560

    Last Modified: 26 Feb 2026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by injecting malicious content into vulnerability code flow.

    Published: 11 Feb 2026
    3.5
    Low

    CVE-2025-14594

    Last Modified: 13 Feb 2026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to view certain pipeline values by querying the API.

    Published: 11 Feb 2026
    3.7
    Low

    CVE-2025-14592

    Last Modified: 13 Feb 2026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized operations by submitting GraphQL mutations through the GLQL API endpoint.

    Published: 11 Feb 2026
    7.3
    High

    CVE-2026-0595

    Last Modified: 17 Apr 2026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to add unauthorized email addresses to victim accounts through HTML injection in test case titles.

    Published: 11 Feb 2026
    7.5
    High

    CVE-2026-0958

    Last Modified: 17 Apr 2026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through memory or CPU exhaustion by bypassing JSON validation middleware limits.

    Published: 11 Feb 2026
    4.3
    Medium

    CVE-2026-1080

    Last Modified: 18 Apr 2026

    GitLab has remediated an issue in GitLab EE affecting all versions from 16.7 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to access iteration data from private descendant groups by querying the iterations API endpoint.

    Published: 11 Feb 2026
    6.5
    Medium

    CVE-2026-2369

    Last Modified: 28 Apr 2026

    A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overread. This can allow an attacker to potentially access sensitive information or cause an application level denial of service.

    Published: 11 Feb 2026
    3.1
    Low

    CVE-2026-2366

    Last Modified: 18 Aug 2026

    A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim's unique identifier (UUID) and the Organizations feature is enabled.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2026-1094

    Last Modified: 18 Apr 2026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 18.8.4 that could have allowed an authenticated developer to hide specially crafted file changes from the WebUI.

    Published: 11 Feb 2026
    3.5
    Low

    CVE-2026-1282

    Last Modified: 18 Apr 2026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to inject malicious content into project labels titles.

    Published: 11 Feb 2026
    6.5
    Medium

    CVE-2026-1387

    Last Modified: 17 Apr 2026

    GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to cause Denial of Service by uploading a malicious file and repeatedly querying it through GraphQl.

    Published: 11 Feb 2026
    6.5
    Medium

    CVE-2026-1456

    Last Modified: 18 Apr 2026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through CPU exhaustion by submitting specially crafted markdown files that trigger exponential processing in markdown preview.

    Published: 11 Feb 2026