VendorsQNAPmedia_streaming_add-onany version
Vulnerabilities

QNAP Media Streaming any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2017-7640
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the system with root privileges.
Published 2018-03-08 · Modified
10.0EPSS 0.031
CVE-2020-36195
SQL Injection Vulnerability in Multimedia Console and the Media Streaming Add-On
Published 2021-04-17 · Modified
9.8EPSS 0.018
CVE-2023-47222
Media Streaming add-on
Published 2024-04-26 · Analyzed
9.8EPSS 0.005
CVE-2025-59383
Media Streaming Add-on
Published 2026-03-20 · Analyzed
9.1EPSS 0.003
CVE-2024-50395
Media Streaming add-on
Published 2024-11-22 · Analyzed
8.8EPSS 0.014
CVE-2017-7641
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not utilize CSRF protections.
Published 2018-03-08 · Modified
8.8EPSS 0.005
CVE-2021-34362
Command Injection Vulnerability in Media Streaming Add-on
Published 2021-10-22 · Modified
8.7EPSS 0.013
CVE-2024-56808
Media Streaming add-on
Published 2026-02-11 · Analyzed
7.8EPSS 0.006
CVE-2023-47220
Media Streaming add-on
Published 2024-05-03 · Analyzed
6.6EPSS 0.012
CVE-2017-7638
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the QNAP NAS.
Published 2018-03-08 · Modified
6.5EPSS 0.007
CVE-2017-7634
Cross-site scripting (XSS) vulnerability in QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to inject arbitrary web script or HTML. The injected code will only be triggered by a crafted link, not the normal page.
Published 2018-03-08 · Modified
6.1EPSS 0.008
CVE-2024-56807
Media Streaming add-on
Published 2026-02-11 · Analyzed
5.5EPSS 0.001