VendorsQNAPqtsany version
Vulnerabilities

QNAP QTS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

107CVEs
CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
Published 2014-09-24 · Analyzed
10.0KEV21 PoCEPSS 1.000
CVE-2014-7169
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
Published 2014-09-25 · Analyzed
10.0KEV15 PoCEPSS 0.999
CVE-2022-27593
DeadBolt Ransomware
Published 2022-09-08 · Analyzed
10.0KEVEPSS 0.879
CVE-2017-6360
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.
Published 2017-03-23 · Modified
10.01 PoCEPSS 0.661
CVE-2017-6361
QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.
Published 2017-03-23 · Modified
10.01 PoCEPSS 0.568
CVE-2017-6359
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors.
Published 2017-03-23 · Modified
10.01 PoCEPSS 0.269
CVE-2017-7876
This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the issue in QTS 4.2.6 build 20170517, QTS 4.3.3.0174 build 20170503 and later versions.
Published 2017-06-15 · Modified
10.0EPSS 0.033
CVE-2017-7640
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the system with root privileges.
Published 2018-03-08 · Modified
10.0EPSS 0.031
CVE-2024-32766
QTS, QuTS hero, QuTScloud
Published 2024-04-26 · Analyzed
10.0EPSS 0.023
CVE-2019-7195
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
Published 2019-12-05 · Analyzed
9.8KEVEPSS 0.897
CVE-2019-7192
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.
Published 2019-12-05 · Analyzed
9.8KEVEPSS 0.881
CVE-2019-7194
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
Published 2019-12-05 · Analyzed
9.8KEVEPSS 0.831
CVE-2020-2509
Command Injection Vulnerability in QTS and QuTS hero
Published 2021-04-17 · Analyzed
9.8KEVEPSS 0.334
CVE-2018-19949
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.
Published 2020-10-28 · Analyzed
9.8KEVEPSS 0.244
CVE-2024-21899
QTS, QuTS hero, QuTScloud
Published 2024-03-08 · Modified
9.8EPSS 0.244
CVE-2017-13067
QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 and QTS 4.3.3.0299 build 20170901. This particular vulnerability allows a remote attacker to execute commands on a QNAP NAS using a transcoding service on port 9251. A remote user does not require any privileges to successfully execute an attack.
Published 2017-09-14 · Modified
9.8EPSS 0.167
CVE-2017-17033
A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
Published 2017-12-21 · Modified
9.8EPSS 0.044
CVE-2017-17028
A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
Published 2017-12-21 · Modified
9.8EPSS 0.033
CVE-2017-17030
A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
Published 2017-12-21 · Modified
9.8EPSS 0.033
CVE-2017-17031
A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
Published 2017-12-21 · Modified
9.8EPSS 0.033
CVE-2017-17029
A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
Published 2017-12-21 · Modified
9.8EPSS 0.033
CVE-2017-17032
A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
Published 2017-12-21 · Modified
9.8EPSS 0.033
CVE-2017-17027
A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
Published 2017-12-21 · Modified
9.8EPSS 0.033
CVE-2019-7198
Command Injection Vulnerability in QTS and QuTS hero
Published 2020-12-10 · Modified
9.8EPSS 0.027
CVE-2022-27596
Vulnerability in QTS
Published 2023-01-30 · Modified
9.8EPSS 0.027
CVE-2018-0712
Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 and their earlier versions could allow remote attackers to run arbitrary commands or install malware on the NAS.
Published 2018-06-21 · Modified
9.8EPSS 0.026
CVE-2021-28804
Command Injection Vulnerabilities in QTS and QuTS hero
Published 2021-07-01 · Modified
9.8EPSS 0.018
CVE-2021-28802
Command Injection Vulnerabilities in QTS and QuTS hero
Published 2021-07-01 · Modified
9.8EPSS 0.018
CVE-2020-36195
SQL Injection Vulnerability in Multimedia Console and the Media Streaming Add-On
Published 2021-04-17 · Modified
9.8EPSS 0.018
CVE-2021-28800
Command Injection Vulnerability in QTS
Published 2021-06-24 · Modified
9.8EPSS 0.014
CVE-2023-23363
QTS
Published 2023-09-22 · Modified
9.8EPSS 0.009
CVE-2025-66276
QTS
Published 2026-06-10 · Analyzed
9.8EPSS 0.003
CVE-2015-6003
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.
Published 2015-10-16 · Modified
9.3EPSS 0.041
CVE-2018-19945
Improper Limitation of a Pathname to a Restricted Directory in QTS
Published 2020-12-31 · Modified
9.1EPSS 0.011
CVE-2020-25847
Command Injection Vulnerability in QTS and QuTS hero
Published 2020-12-29 · Modified
8.8EPSS 0.026
CVE-2021-44051
Command injection
Published 2022-05-05 · Modified
8.8EPSS 0.017
CVE-2023-23362
QTS, QuTS hero, QuTScloud
Published 2023-09-22 · Modified
8.8EPSS 0.016
CVE-2021-28798
Relative Path Traversal Vulnerability in QTS and QuTS hero
Published 2021-05-21 · Modified
8.8EPSS 0.009
CVE-2021-28816
Stack Buffer Overflow Vulnerabilities in QTS, QuTS hero, and QuTScloud
Published 2021-09-10 · Modified
8.8EPSS 0.009
CVE-2021-34360
CSRF Bypass in Proxy Server
Published 2022-05-26 · Modified
8.8EPSS 0.005
1 / 3Next →