Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 1.3 CVE-2025-52872

QTS, QuTS hero_CVE-2025-52872

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they...

QNAP Systems Inc. QTS 5.2.x CVE
LOW 1.3 CVE-2025-52864

QTS, QuTS hero_CVE-2025-52864

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they...

QNAP Systems Inc. QTS 5.2.x CVE
LOW 1.3 CVE-2025-52863

QTS, QuTS hero_CVE-2025-52863

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they...

QNAP Systems Inc. QTS 5.2.x CVE
LOW 1.2 CVE-2025-52431

QTS, QuTS hero_CVE-2025-52431

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administ...

QNAP Systems Inc. QTS 5.2.x CVE
LOW 1.2 CVE-2025-52430

QTS, QuTS hero_CVE-2025-52430

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administ...

QNAP Systems Inc. QTS 5.2.x CVE
LOW 1.2 CVE-2025-52426

QTS, QuTS hero_CVE-2025-52426

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administ...

QNAP Systems Inc. QTS 5.2.x CVE
LOW 1.3 CVE-2025-44013

QTS, QuTS hero_CVE-2025-44013

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user acco...

QNAP Systems Inc. QTS 5.2.x CVE
LOW 2 CVE-2026-21437

eopkg vulnerable to package file list integrity bypass_CVE-2026-21437

eopkg is a Solus package manager implemented in python3. In versions prior to 4.4.0, a malicious package could include files that are not tracked b...

getsolus eopkg < 4.4.0 CVE
LOW 3.4 CVE-2025-69412

CVE-2025-69412_CVE-2025-69412

KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might all...

KDE messagelib CVE
LOW 2.5 CVE-2025-66861

CVE-2025-66861_CVE-2025-66861

An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via c...

n/a n/a n/a CVE