VendorsQNAPqtsall versions
Vulnerabilities

QNAP QTS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

320CVEs
CVE-2018-19957
Insufficient HTTP Security Headers in QTS, QuTS hero, and QuTScloud
Published 2021-09-10 · Modified
6.1EPSS 0.007
CVE-2021-34361
Reflected XSS Vulnerability in Proxy Server
Published 2022-02-25 · Modified
6.1EPSS 0.007
CVE-2021-38674
Reflected XSS Vulnerability in TFTP
Published 2022-01-07 · Modified
6.1EPSS 0.006
CVE-2020-2498
Cross-site scripting vulnerability in QTS and QuTS hero
Published 2020-12-10 · Modified
6.1EPSS 0.006
CVE-2021-44054
Open redirect
Published 2022-05-05 · Modified
6.1EPSS 0.006
CVE-2020-36194
XSS Vulnerability in QTS and QuTS heroCommand Injection Vulnerabilities in QTS and QuTS hero
Published 2021-07-01 · Modified
6.1EPSS 0.006
CVE-2021-28815
Insecure Storage of Sensitive Information in myQNAPcloud Link
Published 2021-06-16 · Modified
6.0EPSS 0.017
CVE-2023-50358
QTS, QuTS hero, QuTScloud
Published 2024-02-13 · Analyzed
5.8EPSS 0.135
CVE-2021-28806
DOM-Based XSS Vulnerability in QTS and QuTS hero
Published 2021-06-03 · Modified
5.7EPSS 0.005
CVE-2018-0719
Security Advisory for Vulnerabilities in QTS
Published 2018-11-27 · Modified
5.5EPSS 0.008
CVE-2023-45027
QTS, QuTS hero, QuTScloud
Published 2024-02-02 · Modified
5.5EPSS 0.005
CVE-2023-45026
QTS, QuTS hero, QuTScloud
Published 2024-02-02 · Modified
5.5EPSS 0.005
CVE-2023-41274
QTS, QuTS hero, QuTScloud
Published 2024-02-02 · Modified
5.5EPSS 0.004
CVE-2023-45028
QTS, QuTS hero, QuTScloud
Published 2024-02-02 · Modified
5.5EPSS 0.004
CVE-2024-50405
QTS, QuTS hero
Published 2025-03-07 · Analyzed
5.5EPSS 0.004
CVE-2024-56805
QTS, QuTS hero
Published 2025-06-06 · Analyzed
5.4EPSS 0.004
CVE-2025-58465
Download Station
Published 2025-11-07 · Analyzed
5.4EPSS 0.002
CVE-2017-7630
QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensitive information (firmware version and running services) via a request to sysinfoReq.cgi.
Published 2018-03-27 · Modified
5.3EPSS 0.010
CVE-2021-38693
Path Traversal in thttpd
Published 2022-05-05 · Modified
5.3EPSS 0.010
CVE-2023-34973
QTS, QuTS hero
Published 2023-08-24 · Modified
5.3EPSS 0.005
CVE-2024-48866
QTS, QuTS hero
Published 2024-12-06 · Analyzed
5.3EPSS 0.004
CVE-2024-53692
QTS, QuTS hero
Published 2025-03-07 · Analyzed
5.1EPSS 0.008
CVE-2024-37043
QTS, QuTS hero
Published 2024-11-22 · Analyzed
5.1EPSS 0.007
CVE-2024-37048
QTS, QuTS hero
Published 2024-11-22 · Analyzed
5.1EPSS 0.006
CVE-2024-37042
QTS, QuTS hero
Published 2024-11-22 · Analyzed
5.1EPSS 0.006
CVE-2024-37045
QTS, QuTS hero
Published 2024-11-22 · Analyzed
5.1EPSS 0.006
CVE-2025-33032
QTS, QuTS hero
Published 2025-08-29 · Analyzed
5.1EPSS 0.005
CVE-2025-47213
QTS, QuTS hero
Published 2025-10-03 · Analyzed
5.1EPSS 0.005
CVE-2025-47214
QTS
Published 2025-10-03 · Analyzed
5.1EPSS 0.005
CVE-2025-48726
QTS, QuTS hero
Published 2025-10-03 · Analyzed
5.1EPSS 0.005
CVE-2025-48727
QTS, QuTS hero
Published 2025-10-03 · Analyzed
5.1EPSS 0.005
CVE-2025-48728
QTS, QuTS hero
Published 2025-10-03 · Analyzed
5.1EPSS 0.005
CVE-2025-48729
QTS, QuTS hero
Published 2025-10-03 · Analyzed
5.1EPSS 0.005
CVE-2025-52424
QTS, QuTS hero
Published 2025-10-03 · Analyzed
5.1EPSS 0.005
CVE-2025-52427
QTS, QuTS hero
Published 2025-10-03 · Analyzed
5.1EPSS 0.005
CVE-2024-53696
QuLog Center
Published 2025-03-07 · Analyzed
5.1EPSS 0.004
CVE-2025-47205
QTS, QuTS hero
Published 2026-02-11 · Analyzed
5.1EPSS 0.004
CVE-2025-52860
QTS, QuTS hero
Published 2025-10-03 · Analyzed
5.1EPSS 0.004
CVE-2025-52428
QTS
Published 2025-10-03 · Analyzed
5.1EPSS 0.004
CVE-2025-52858
QTS, QuTS hero
Published 2025-10-03 · Analyzed
5.1EPSS 0.004
← Prev7 / 8Next →