📦 Qsync Central

by Qnap

🔍 What is Qsync Central?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-57709

HIGH CVSS 8.1 Feb 11, 2026

A buffer overflow vulnerability in Qsync Central allows authenticated remote attackers to modify memory or crash processes. This affects all Qsync Central installations before version 5.0.0.4. Organiz...

CVE-2025-52869

HIGH CVSS 8.1 Feb 11, 2026

A buffer overflow vulnerability in Qsync Central allows authenticated remote attackers to modify memory or crash processes. This affects all Qsync Central installations before version 5.0.0.4. Organiz...

CVE-2025-30276

HIGH CVSS 8.8 Feb 11, 2026

An out-of-bounds write vulnerability in Qsync Central allows authenticated remote attackers to modify or corrupt memory. This affects QNAP Qsync Central users who haven't updated to the patched versio...

CVE-2025-48723

HIGH CVSS 8.1 Feb 11, 2026

A buffer overflow vulnerability in Qsync Central allows authenticated remote attackers to modify memory or crash processes. This affects all QNAP Qsync Central deployments before version 5.0.0.4. Atta...

CVE-2025-53595

HIGH CVSS 8.8 Oct 3, 2025

An SQL injection vulnerability in Qsync Central allows authenticated attackers to execute arbitrary SQL commands. This could lead to unauthorized data access, modification, or command execution. Organ...

CVE-2025-54153

HIGH CVSS 8.8 Oct 3, 2025

An SQL injection vulnerability in Qsync Central allows authenticated remote attackers to execute arbitrary SQL commands. This could lead to unauthorized data access, modification, or code execution. O...

CVE-2025-44014

HIGH CVSS 8.8 Oct 3, 2025

An out-of-bounds write vulnerability in Qsync Central allows authenticated remote attackers to modify or corrupt memory. This affects QNAP Qsync Central installations before version 5.0.0.1. Attackers...

CVE-2025-30277

HIGH CVSS 8.8 Aug 29, 2025

An improper certificate validation vulnerability in Qsync Central allows attackers with user accounts to bypass certificate checks and potentially intercept or manipulate communications. This affects ...

CVE-2025-29893

HIGH CVSS 8.8 Aug 29, 2025

An SQL injection vulnerability in Qsync Central allows authenticated remote attackers to execute arbitrary SQL commands. This could lead to unauthorized data access, modification, or command execution...

CVE-2024-50404

HIGH CVSS 8.8 Dec 6, 2024

This CVE describes a link following vulnerability in Qsync Central that allows remote attackers with user access to traverse the file system to unintended locations. This affects organizations using v...

CVE-2025-58467

MEDIUM CVSS 6.5 Feb 11, 2026

A relative path traversal vulnerability in Qsync Central allows authenticated attackers to read arbitrary files on the system. This affects all Qsync Central installations before version 5.0.0.4. Atta...

CVE-2025-58470

MEDIUM CVSS 6.5 Feb 11, 2026

A path traversal vulnerability in Qsync Central allows authenticated attackers to read arbitrary files on the system. This affects all Qsync Central installations before version 5.0.0.4. Attackers nee...

CVE-2025-57711

MEDIUM CVSS 4.9 Feb 11, 2026

This vulnerability in Qsync Central allows authenticated administrators to allocate resources without limits, potentially causing denial of service by starving other systems of those same resources. I...

CVE-2025-58471

MEDIUM CVSS 4.9 Feb 11, 2026

This vulnerability in Qsync Central allows authenticated attackers with administrator privileges to allocate system resources without limits, potentially causing denial-of-service conditions. It affec...

CVE-2025-57708

MEDIUM CVSS 6.5 Feb 11, 2026

This vulnerability in Qsync Central allows authenticated remote attackers to perform resource exhaustion attacks by allocating resources without limits. Attackers with valid user accounts can consume ...

CVE-2025-54148

MEDIUM CVSS 6.5 Feb 11, 2026

A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This affects organizations using QNAP's Qsync Central software fo...

CVE-2025-54150

MEDIUM CVSS 5.5 Feb 11, 2026

An uncontrolled resource consumption vulnerability in Qsync Central allows local attackers with user accounts to launch denial-of-service attacks by exhausting system resources. This affects all Qsync...

CVE-2025-54151

MEDIUM CVSS 5.5 Feb 11, 2026

An uncontrolled resource consumption vulnerability in Qsync Central allows local attackers with user accounts to launch denial-of-service attacks by exhausting system resources. This affects all Qsync...

CVE-2025-53598

MEDIUM CVSS 6.5 Feb 11, 2026

A NULL pointer dereference vulnerability in Qsync Central allows remote attackers with valid user credentials to cause a denial-of-service condition. This affects organizations using vulnerable versio...

CVE-2025-54147

MEDIUM CVSS 6.5 Feb 11, 2026

A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This affects organizations using vulnerable versions of Qsync Cen...

CVE-2025-47209

MEDIUM CVSS 6.5 Feb 11, 2026

A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This affects organizations using vulnerable versions of Qsync Cen...

CVE-2025-30266

MEDIUM CVSS 6.5 Feb 11, 2026

A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This affects organizations using vulnerable versions of Qsync Cen...

CVE-2025-57712

MEDIUM CVSS 6.5 Nov 7, 2025

A path traversal vulnerability in Qsync Central allows authenticated attackers to read arbitrary files on the system. This affects all Qsync Central installations before version 5.0.0.3. Organizations...

CVE-2025-52867

MEDIUM CVSS 6.5 Oct 3, 2025

An uncontrolled resource consumption vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This affects all QNAP Qsync Central installations befor...

CVE-2025-44008

MEDIUM CVSS 6.5 Oct 3, 2025

A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service by crashing the service. This affects all QNAP users running vulnerable versi...

CVE-2025-44010

MEDIUM CVSS 6.5 Oct 3, 2025

A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This affects all QNAP Qsync Central installations before version ...

CVE-2025-44012

MEDIUM CVSS 6.5 Oct 3, 2025

A resource exhaustion vulnerability in Qsync Central allows authenticated attackers to consume system resources, potentially causing denial of service. This affects all QNAP Qsync Central deployments ...

CVE-2025-33040

MEDIUM CVSS 6.5 Oct 3, 2025

This vulnerability in Qsync Central allows authenticated remote attackers to allocate resources without limits, potentially causing denial of service by preventing other systems from accessing the sam...

CVE-2025-44006

MEDIUM CVSS 6.5 Oct 3, 2025

This vulnerability in Qsync Central allows authenticated remote attackers to perform resource exhaustion attacks by allocating resources without limits. Attackers with user accounts can prevent legiti...

CVE-2025-33039

MEDIUM CVSS 6.5 Oct 3, 2025

This vulnerability in Qsync Central allows authenticated remote attackers to exhaust system resources through unlimited allocation, potentially causing denial of service. It affects QNAP Qsync Central...

CVE-2025-33036

MEDIUM CVSS 6.5 Aug 29, 2025

A path traversal vulnerability in Qsync Central allows authenticated remote attackers to read arbitrary files on the system. This affects all QNAP users running vulnerable versions of Qsync Central. A...

CVE-2025-33038

MEDIUM CVSS 6.5 Aug 29, 2025

A path traversal vulnerability in Qsync Central allows authenticated remote attackers to read arbitrary files on the system. This affects all Qsync Central installations before version 4.5.0.7. Attack...

CVE-2025-30275

MEDIUM CVSS 6.5 Aug 29, 2025

A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This affects organizations using vulnerable versions of Qsync Cen...

CVE-2025-30263

MEDIUM CVSS 6.5 Aug 29, 2025

A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service by crashing the service. This affects all QNAP Qsync Central installations be...

CVE-2025-30261

MEDIUM CVSS 6.5 Aug 29, 2025

This vulnerability in Qsync Central allows authenticated remote attackers to perform resource exhaustion attacks by allocating resources without limits. Attackers with user accounts can prevent legiti...

CVE-2025-29898

MEDIUM CVSS 6.5 Aug 29, 2025

An uncontrolled resource consumption vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This affects all QNAP Qsync Central deployments running...