VendorsQNAPqtsany version
Vulnerabilities

QNAP QTS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

107CVEs
CVE-2017-7641
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not utilize CSRF protections.
Published 2018-03-08 · Modified
8.8EPSS 0.005
CVE-2023-34971
QTS, QuTS hero
Published 2023-08-24 · Modified
8.8EPSS 0.001
CVE-2023-51364
QTS, QuTS hero, QuTScloud
Published 2024-04-26 · Analyzed
8.7EPSS 0.397
CVE-2023-51365
QTS, QuTS hero, QuTScloud
Published 2024-04-26 · Analyzed
8.7EPSS 0.348
CVE-2026-22893
QTS, QuTS hero
Published 2026-06-10 · Analyzed
8.6EPSS 0.011
CVE-2025-66279
QTS, QuTS hero
Published 2026-06-10 · Analyzed
8.6EPSS 0.011
CVE-2025-66273
QTS, QuTS hero
Published 2026-06-10 · Analyzed
8.6EPSS 0.011
CVE-2023-34980
QTS, QuTS hero
Published 2024-03-08 · Analyzed
8.4EPSS 0.009
CVE-2023-47218
QTS, QuTS hero, QuTScloud
Published 2024-02-13 · Analyzed
8.3EPSS 0.899
CVE-2024-21905
QTS, QuTS hero, QuTScloud
Published 2024-04-26 · Analyzed
8.2EPSS 0.005
CVE-2021-44052
Arbitrary file read
Published 2022-05-05 · Modified
8.1EPSS 0.016
CVE-2018-19943
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later
Published 2020-10-28 · Analyzed
8.0KEVEPSS 0.215
CVE-2013-7174
Absolute path traversal vulnerability in cgi-bin/jc.cgi in QNAP QTS before 4.1.0 allows remote attackers to read arbitrary files via a full pathname in the f parameter.
Published 2014-01-09 · Modified
7.8EPSS 0.021
CVE-2017-5227
QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by reading data in an XOR format within the /etc/config/uLinux.conf configuration file.
Published 2017-03-23 · Modified
7.51 PoCEPSS 0.064
CVE-2024-27124
QTS, QuTS hero, QuTScloud
Published 2024-04-26 · Analyzed
7.5EPSS 0.014
CVE-2018-0728
This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerability, QNAP recommend updating QTS and Helpdesk to their latest versions.
Published 2019-12-04 · Modified
7.5EPSS 0.013
CVE-2017-7629
QNAP QTS before 4.2.6 build 20170517 has a flaw in the change password function.
Published 2017-06-15 · Modified
7.5EPSS 0.010
CVE-2018-19944
Cleartext Transmission of Sensitive Information in SNMP
Published 2020-12-31 · Modified
7.5EPSS 0.008
CVE-2018-19941
Cleartext Storage of Sensitive Information in Cookies
Published 2020-12-31 · Modified
7.5EPSS 0.007
CVE-2023-32974
QTS, QuTS hero, QuTScloud
Published 2023-10-13 · Modified
7.5EPSS 0.006
CVE-2022-27600
QTS, QuTS hero, QuTScloud
Published 2024-12-19 · Analyzed
7.5EPSS 0.006
CVE-2024-13086
QTS, QuTS hero
Published 2025-03-07 · Analyzed
7.5EPSS 0.004
CVE-2020-2490
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.
Published 2020-11-16 · Modified
7.2EPSS 0.022
CVE-2021-34343
Buffer Overflow Vulnerability in QTS, QuTS hero, and QuTScloud
Published 2021-09-10 · Modified
7.2EPSS 0.020
CVE-2020-2508
Command Injection Vulnerability in QTS and QuTS hero
Published 2021-01-11 · Modified
7.2EPSS 0.018
CVE-2020-2492
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.
Published 2020-11-16 · Modified
7.2EPSS 0.017
CVE-2023-23355
QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances), QVR
Published 2023-03-29 · Modified
7.2EPSS 0.012
CVE-2026-24719
QTS, QuTS hero
Published 2026-06-10 · Modified
7.2EPSS 0.010
CVE-2023-32971
QTS, QuTS hero, QuTScloud
Published 2023-10-06 · Modified
7.2EPSS 0.005
CVE-2023-32972
QTS, QuTS hero, QuTScloud
Published 2023-10-06 · Modified
7.2EPSS 0.005
CVE-2023-32973
QTS, QuTS hero, QuTScloud
Published 2023-10-13 · Modified
7.2EPSS 0.005
CVE-2025-66281
QTS, QuTS hero
Published 2026-06-10 · Analyzed
7.2EPSS 0.005
CVE-2025-66280
QTS, QuTS hero
Published 2026-06-10 · Analyzed
7.2EPSS 0.004
CVE-2026-24716
QTS, QuTS hero
Published 2026-06-10 · Modified
7.2EPSS 0.003
CVE-2021-34359
Stored XSS Vulnerability in Proxy Server
Published 2022-02-25 · Modified
6.9EPSS 0.006
CVE-2024-21900
QTS, QuTS hero, QuTScloud
Published 2024-03-08 · Modified
6.5EPSS 0.094
CVE-2017-7638
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the QNAP NAS.
Published 2018-03-08 · Modified
6.5EPSS 0.007
CVE-2026-24717
QTS, QuTS hero
Published 2026-06-10 · Modified
6.5EPSS 0.004
CVE-2023-34972
QTS, QuTS hero and QuTScloud
Published 2023-08-24 · Modified
6.5EPSS 0.002
CVE-2018-19953
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.
Published 2020-10-28 · Analyzed
6.1KEVEPSS 0.288
← Prev2 / 3Next →