Every published CVE from the last 120 days with CVSS score, vendor and product, cross-referenced against CISA's Known Exploited Vulnerabilities catalog. 10 added to KEV in the last 7 days.
| CVE | CVSS | Severity | Vendor / product | Summary | Published |
|---|---|---|---|---|---|
| CVE-2025-62843 | 6.8 | medium | qnap / qurouter | An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect Q | 169d ago |
| CVE-2026-22902 | 6.7 | medium | qnap / qunetswitch | A command injection vulnerability has been reported to affect QuNetSwitch. | 169d ago |
| CVE-2025-62846 | 6.7 | medium | qnap / qurouter | An SQL injection vulnerability has been reported to affect QHora. | 169d ago |
| CVE-2025-62845 | 6.7 | medium | qnap / qurouter | An improper neutralization of escape, meta, or control sequences vulnerability has been reported to affect QHora. | 169d ago |
| CVE-2025-62844 | 5.5 | medium | qnap / qurouter | A weak authentication vulnerability has been reported to affect QHora. | 169d ago |
| CVE-2026-22895 | 4.8 | medium | qnap / quftp | A cross-site scripting (XSS) vulnerability has been reported to affect QuFTP Service. | 169d ago |
Sources: NIST National Vulnerability Database (descriptions, CVSS, CPE) and CISA Known Exploited Vulnerabilities catalog (exploitation status). Both are United States government works in the public domain. Data refreshes daily; KEV hourly.