VendorsQNAPqtsall versions
Vulnerabilities

QNAP QTS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

320CVEs
CVE-2024-50397
QTS, QuTS hero
Published 2024-11-22 · Analyzed
8.8EPSS 0.006
CVE-2024-50396
QTS, QuTS hero
Published 2024-11-22 · Analyzed
8.8EPSS 0.006
CVE-2024-32763
QTS, QuTS hero
Published 2024-09-06 · Analyzed
8.8EPSS 0.006
CVE-2023-47568
QTS, QuTS hero, QuTScloud
Published 2024-02-02 · Modified
8.8EPSS 0.005
CVE-2021-34360
CSRF Bypass in Proxy Server
Published 2022-05-26 · Modified
8.8EPSS 0.005
CVE-2017-7641
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not utilize CSRF protections.
Published 2018-03-08 · Modified
8.8EPSS 0.005
CVE-2023-51367
QTS, QuTS hero
Published 2024-09-06 · Analyzed
8.8EPSS 0.004
CVE-2023-34971
QTS, QuTS hero
Published 2023-08-24 · Modified
8.8EPSS 0.001
CVE-2023-51364
QTS, QuTS hero, QuTScloud
Published 2024-04-26 · Analyzed
8.7EPSS 0.397
CVE-2023-51365
QTS, QuTS hero, QuTScloud
Published 2024-04-26 · Analyzed
8.7EPSS 0.348
CVE-2021-34362
Command Injection Vulnerability in Media Streaming Add-on
Published 2021-10-22 · Modified
8.7EPSS 0.013
CVE-2023-23354
QuLog Center
Published 2024-12-19 · Analyzed
8.7EPSS 0.005
CVE-2023-51366
QTS, QuTS hero
Published 2024-09-06 · Analyzed
8.7EPSS 0.005
CVE-2024-48868
QTS, QuTS hero
Published 2024-12-06 · Analyzed
8.7EPSS 0.004
CVE-2026-22893
QTS, QuTS hero
Published 2026-06-10 · Analyzed
8.6EPSS 0.011
CVE-2025-66273
QTS, QuTS hero
Published 2026-06-10 · Analyzed
8.6EPSS 0.011
CVE-2025-66279
QTS, QuTS hero
Published 2026-06-10 · Analyzed
8.6EPSS 0.011
CVE-2023-34980
QTS, QuTS hero
Published 2024-03-08 · Analyzed
8.4EPSS 0.009
CVE-2023-47218
QTS, QuTS hero, QuTScloud
Published 2024-02-13 · Analyzed
8.3EPSS 0.899
CVE-2024-21905
QTS, QuTS hero, QuTScloud
Published 2024-04-26 · Analyzed
8.2EPSS 0.005
CVE-2021-44052
Arbitrary file read
Published 2022-05-05 · Modified
8.1EPSS 0.016
CVE-2025-62848
QTS, QuTS hero
Published 2025-12-16 · Analyzed
8.1EPSS 0.009
CVE-2023-50363
QTS, QuTS hero
Published 2024-04-26 · Modified
8.1EPSS 0.004
CVE-2025-48725
QuTS hero
Published 2026-02-11 · Analyzed
8.1EPSS 0.004
CVE-2025-30273
QTS, QuTS hero
Published 2025-08-29 · Analyzed
8.1EPSS 0.004
CVE-2024-21902
QTS, QuTS hero
Published 2024-05-21 · Modified
8.1EPSS 0.004
CVE-2025-52872
QTS, QuTS hero
Published 2026-01-02 · Analyzed
8.1EPSS 0.003
CVE-2025-52864
QTS, QuTS hero
Published 2026-01-02 · Analyzed
8.1EPSS 0.003
CVE-2025-52863
QTS, QuTS hero
Published 2026-01-02 · Analyzed
8.1EPSS 0.003
CVE-2018-19943
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later
Published 2020-10-28 · Analyzed
8.0KEVEPSS 0.215
CVE-2013-7174
Absolute path traversal vulnerability in cgi-bin/jc.cgi in QNAP QTS before 4.1.0 allows remote attackers to read arbitrary files via a full pathname in the f parameter.
Published 2014-01-09 · Modified
7.8EPSS 0.021
CVE-2018-14748
Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to power off the NAS.
Published 2018-11-28 · Modified
7.8EPSS 0.013
CVE-2024-14026
QTS, QuTS hero
Published 2026-03-11 · Analyzed
7.8EPSS 0.006
CVE-2024-38641
QTS, QuTS hero
Published 2024-09-06 · Analyzed
7.8EPSS 0.005
CVE-2023-39298
QTS, QuTS hero
Published 2024-09-06 · Analyzed
7.8EPSS 0.001
CVE-2021-28807
Post-Authentication Reflected XSS Vulnerability in Q'center
Published 2021-06-03 · Modified
7.7EPSS 0.014
CVE-2017-5227
QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by reading data in an XOR format within the /etc/config/uLinux.conf configuration file.
Published 2017-03-23 · Modified
7.51 PoCEPSS 0.064
CVE-2018-0722
Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier in QTS 4.2.6 could allow remote attackers to access sensitive information on the device.
Published 2019-02-01 · Modified
7.5EPSS 0.017
CVE-2023-39296
QTS, QuTS hero
Published 2024-01-05 · Modified
7.5EPSS 0.016
CVE-2024-27124
QTS, QuTS hero, QuTScloud
Published 2024-04-26 · Analyzed
7.5EPSS 0.014
← Prev3 / 8Next →