Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.2 CVE-2025-58465

Download Station_CVE-2025-58465

A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a remote attacker gains a user account, they can then e...

QNAP Systems Inc. Download Station 5.10.x CVE
LOW 2.3 CVE-2025-58463

Download Station_CVE-2025-58463

A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an administrator account, they can...

QNAP Systems Inc. Download Station 5.10.x CVE
LOW 2.2 CVE-2025-57706

File Station 5_CVE-2025-57706

A cross-site scripting (XSS) vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exp...

QNAP Systems Inc. File Station 5 5.5.x CVE
LOW 2.2 CVE-2025-54168

QuLog Center_CVE-2025-54168

A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If a remote attacker gains an administrator account, they can ...

QNAP Systems Inc. QuLog Center 1.8.x.x CVE
LOW 0.6 CVE-2025-53412

File Station 5_CVE-2025-53412

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then explo...

QNAP Systems Inc. File Station 5 5.5.x CVE
LOW 1.2 CVE-2025-53411

File Station 5_CVE-2025-53411

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an adm...

QNAP Systems Inc. File Station 5 5.5.x CVE
LOW 1.3 CVE-2025-53408

File Station 5_CVE-2025-53408

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then explo...

QNAP Systems Inc. File Station 5 5.5.x CVE
LOW 1.3 CVE-2025-52865

File Station 5_CVE-2025-52865

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then explo...

QNAP Systems Inc. File Station 5 5.5.x CVE
LOW 3.7 CVE-2025-48985

CVE-2025-48985_CVE-2025-48985

A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass fil...

Vercel AI SDK 5.0.51 CVE
LOW 2.6 CVE-2025-64326

Weblate leaks the IP of project members inviting users to assume reviewer roles in Audit log_CVE-2025-64326

Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the ...

WeblateOrg weblate < 5.14.1 CVE