VendorsQNAPqtsany version
Vulnerabilities

QNAP QTS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

107CVEs
CVE-2020-2495
Cross-site scripting vulnerability in QTS and QuTS hero
Published 2020-12-10 · Modified
6.1EPSS 0.010
CVE-2020-2496
Cross-site scripting vulnerability in QTS and QuTS hero
Published 2020-12-10 · Modified
6.1EPSS 0.010
CVE-2015-5664
Cross-site scripting (XSS) vulnerability in File Station in QNAP QTS before 4.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2016-07-03 · Modified
6.1EPSS 0.010
CVE-2020-2497
Cross-site scripting vulnerability in QTS and QuTS hero
Published 2020-12-10 · Modified
6.1EPSS 0.010
CVE-2017-7634
Cross-site scripting (XSS) vulnerability in QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to inject arbitrary web script or HTML. The injected code will only be triggered by a crafted link, not the normal page.
Published 2018-03-08 · Modified
6.1EPSS 0.008
CVE-2021-44053
Reflected XSS
Published 2022-05-05 · Modified
6.1EPSS 0.008
CVE-2018-19942
Cross-site Scripting Vulnerability in File Station
Published 2021-04-16 · Modified
6.1EPSS 0.007
CVE-2018-19957
Insufficient HTTP Security Headers in QTS, QuTS hero, and QuTScloud
Published 2021-09-10 · Modified
6.1EPSS 0.007
CVE-2021-34361
Reflected XSS Vulnerability in Proxy Server
Published 2022-02-25 · Modified
6.1EPSS 0.007
CVE-2021-38674
Reflected XSS Vulnerability in TFTP
Published 2022-01-07 · Modified
6.1EPSS 0.006
CVE-2020-2498
Cross-site scripting vulnerability in QTS and QuTS hero
Published 2020-12-10 · Modified
6.1EPSS 0.006
CVE-2021-44054
Open redirect
Published 2022-05-05 · Modified
6.1EPSS 0.006
CVE-2020-36194
XSS Vulnerability in QTS and QuTS heroCommand Injection Vulnerabilities in QTS and QuTS hero
Published 2021-07-01 · Modified
6.1EPSS 0.006
CVE-2023-50358
QTS, QuTS hero, QuTScloud
Published 2024-02-13 · Analyzed
5.8EPSS 0.135
CVE-2021-28806
DOM-Based XSS Vulnerability in QTS and QuTS hero
Published 2021-06-03 · Modified
5.7EPSS 0.005
CVE-2021-38693
Path Traversal in thttpd
Published 2022-05-05 · Modified
5.3EPSS 0.010
CVE-2023-34973
QTS, QuTS hero
Published 2023-08-24 · Modified
5.3EPSS 0.005
CVE-2024-53696
QuLog Center
Published 2025-03-07 · Analyzed
5.1EPSS 0.004
CVE-2023-32970
QTS, QuTS hero, QuTScloud
Published 2023-10-13 · Modified
4.9EPSS 0.005
CVE-2023-32969
Network & Virtual Switch
Published 2024-03-08 · Analyzed
4.9EPSS 0.003
CVE-2019-7185
This cross-site scripting (XSS) vulnerability in Music Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Music Station to their latest versions.
Published 2019-12-05 · Modified
4.8EPSS 0.015
CVE-2019-7184
This cross-site scripting (XSS) vulnerability in Video Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Video Station to their latest versions.
Published 2019-12-05 · Modified
4.8EPSS 0.015
CVE-2024-21901
myQNAPcloud
Published 2024-03-08 · Modified
4.7EPSS 0.187
CVE-2023-39301
QTS, QuTS hero, QuTScloud
Published 2023-11-03 · Modified
4.3EPSS 0.003
CVE-2024-32765
QTS, QuTS hero
Published 2024-08-09 · Analyzed
4.2EPSS 0.002
CVE-2022-27597
QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances)
Published 2023-03-29 · Modified
2.7EPSS 0.007
CVE-2022-27598
QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances)
Published 2023-03-29 · Modified
2.7EPSS 0.007
← Prev3 / 3