QNAP MusicStation and MalwareRemover are affected by arbitrary file upload and command injection vulnerabilities, leading to pre-authentication remote command execution with root privileges on the NAS.
dddda20f7202ce5358af06526c5259d1f75a28b841ba2fcc6fd3fd23682bb880
TCPDF versions 6.2.19 and below suffer from a deserialization vulnerability that can allow for remote code execution.
c4935b1bec468d4305cf1499300d42f521083fed9900cd9b61485ae84fe7a467