VendorsQNAPqtsall versions
Vulnerabilities

QNAP QTS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

320CVEs
CVE-2018-0728
This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerability, QNAP recommend updating QTS and Helpdesk to their latest versions.
Published 2019-12-04 · Modified
7.5EPSS 0.013
CVE-2018-19952
If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.
Published 2020-11-02 · Modified
7.5EPSS 0.013
CVE-2018-14747
NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to crash the NAS media server.
Published 2018-11-28 · Modified
7.5EPSS 0.013
CVE-2017-7629
QNAP QTS before 4.2.6 build 20170517 has a flaw in the change password function.
Published 2017-06-15 · Modified
7.5EPSS 0.010
CVE-2018-19944
Cleartext Transmission of Sensitive Information in SNMP
Published 2020-12-31 · Modified
7.5EPSS 0.008
CVE-2025-62847
QTS, QuTS hero
Published 2025-12-16 · Analyzed
7.5EPSS 0.008
CVE-2018-19941
Cleartext Storage of Sensitive Information in Cookies
Published 2020-12-31 · Modified
7.5EPSS 0.007
CVE-2023-32974
QTS, QuTS hero, QuTScloud
Published 2023-10-13 · Modified
7.5EPSS 0.006
CVE-2022-27600
QTS, QuTS hero, QuTScloud
Published 2024-12-19 · Analyzed
7.5EPSS 0.006
CVE-2024-48867
QTS, QuTS hero
Published 2024-12-06 · Analyzed
7.5EPSS 0.005
CVE-2025-9110
QTS, QuTS hero
Published 2026-01-02 · Analyzed
7.5EPSS 0.005
CVE-2024-13086
QTS, QuTS hero
Published 2025-03-07 · Analyzed
7.5EPSS 0.004
CVE-2024-48865
QTS, QuTS hero
Published 2024-12-06 · Analyzed
7.5EPSS 0.002
CVE-2020-2490
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.
Published 2020-11-16 · Modified
7.2EPSS 0.022
CVE-2021-34343
Buffer Overflow Vulnerability in QTS, QuTS hero, and QuTScloud
Published 2021-09-10 · Modified
7.2EPSS 0.020
CVE-2020-2508
Command Injection Vulnerability in QTS and QuTS hero
Published 2021-01-11 · Modified
7.2EPSS 0.018
CVE-2020-2492
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.
Published 2020-11-16 · Modified
7.2EPSS 0.017
CVE-2023-23367
QTS, QuTS hero, QuTScloud
Published 2023-11-10 · Modified
7.2EPSS 0.015
CVE-2025-47212
QTS, QuTS hero
Published 2025-10-03 · Analyzed
7.2EPSS 0.013
CVE-2023-23355
QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances), QVR
Published 2023-03-29 · Modified
7.2EPSS 0.012
CVE-2023-39300
QTS
Published 2024-09-06 · Analyzed
7.2EPSS 0.012
CVE-2023-47566
QTS, QuTS hero, QuTScloud
Published 2024-02-02 · Modified
7.2EPSS 0.012
CVE-2023-39294
QTS, QuTS hero
Published 2024-01-05 · Modified
7.2EPSS 0.011
CVE-2023-47567
QTS, QuTS hero, QuTScloud
Published 2024-02-02 · Modified
7.2EPSS 0.011
CVE-2023-34979
QTS, QuTS hero
Published 2024-09-06 · Analyzed
7.2EPSS 0.011
CVE-2023-39302
QTS, QuTS hero, QuTScloud
Published 2024-02-02 · Modified
7.2EPSS 0.011
CVE-2026-24719
QTS, QuTS hero
Published 2026-06-10 · Modified
7.2EPSS 0.010
CVE-2023-41282
QTS, QuTS hero, QuTScloud
Published 2024-02-02 · Modified
7.2EPSS 0.010
CVE-2023-41283
QTS, QuTS hero, QuTScloud
Published 2024-02-02 · Modified
7.2EPSS 0.010
CVE-2023-41281
QTS, QuTS hero, QuTScloud
Published 2024-02-02 · Modified
7.2EPSS 0.010
CVE-2023-32975
QTS, QuTS hero
Published 2023-12-08 · Modified
7.2EPSS 0.009
CVE-2024-37044
QTS, QuTS hero
Published 2024-11-22 · Analyzed
7.2EPSS 0.009
CVE-2024-37041
QTS, QuTS hero
Published 2024-11-22 · Analyzed
7.2EPSS 0.009
CVE-2023-32968
QTS, QuTS hero
Published 2023-12-08 · Modified
7.2EPSS 0.008
CVE-2023-45040
QTS, QuTS hero
Published 2024-01-05 · Modified
7.2EPSS 0.006
CVE-2023-45043
QTS, QuTS hero
Published 2024-01-05 · Modified
7.2EPSS 0.006
CVE-2023-45039
QTS, QuTS hero
Published 2024-01-05 · Modified
7.2EPSS 0.006
CVE-2023-45042
QTS, QuTS hero
Published 2024-01-05 · Modified
7.2EPSS 0.006
CVE-2023-45044
QTS, QuTS hero
Published 2024-01-05 · Modified
7.2EPSS 0.006
CVE-2023-45041
QTS, QuTS hero
Published 2024-01-05 · Modified
7.2EPSS 0.006
← Prev4 / 8Next →