VendorsQNAPhelpdeskany version
Vulnerabilities

QNAP Helpdesk any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2020-2507
command injection vulnerability in Helpdesk
Published 2021-02-03 · Modified
9.8EPSS 0.030
CVE-2018-0714
Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 20180528 and their earlier versions could allow remote attackers to run arbitrary commands in the compromised application.
Published 2018-08-13 · Modified
9.8EPSS 0.023
CVE-2020-2506
improper access control vulnerability in Helpdesk
Published 2021-02-03 · Analyzed
9.8KEVEPSS 0.020
CVE-2020-2500
This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive data on QNAP Kayako server with API keys. We have replaced the API key to mitigate the vulnerability, and already fixed the issue in Helpdesk 3.0.1 and later versions.
Published 2020-07-01 · Modified
9.8EPSS 0.007
CVE-2021-28814
Improper Access Control Vulnerability in Helpdesk
Published 2021-06-11 · Modified
8.8EPSS 0.012
CVE-2024-50394
Helpdesk
Published 2025-03-07 · Analyzed
8.8EPSS 0.003
CVE-2018-0728
This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerability, QNAP recommend updating QTS and Helpdesk to their latest versions.
Published 2019-12-04 · Modified
7.5EPSS 0.013
CVE-2018-19947
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sensitive information. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.
Published 2020-09-11 · Modified
6.5EPSS 0.008
CVE-2018-19948
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could allow attackers to force NAS users to execute unintentional actions through a web application. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.
Published 2020-09-11 · Modified
6.5EPSS 0.003
CVE-2018-19946
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.
Published 2020-09-11 · Modified
5.9EPSS 0.003
CVE-2024-27125
Helpdesk
Published 2024-09-06 · Analyzed
4.8EPSS 0.002