QNAP Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for QNAP products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
18
In CISA KEV
12
Beyond CISA KEV
6
Sensor Observed
0
Virtual Patch Available
0
QNAP KEVs Added by Year
18 QNAP KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2023-50358
QTS, QuTS hero, QuTScloud |
QTS, QuTS hero, QuTScloud | High | Not in CISA | 26 Oct 2025 |
|
CVE-2023-45038
Music Station |
Music Station | High | Not in CISA | 21 Aug 2025 |
|
CVE-2020-2507
command injection vulnerability in Helpdesk |
Helpdesk | High | Not in CISA | 16 Aug 2025 |
|
CVE-2023-47218
QTS, QuTS hero, QuTScloud |
QTS, QuTS hero, QuTScloud | High | Not in CISA | 05 Jun 2025 |
|
CVE-2024-21899
QTS, QuTS hero, QuTScloud |
QTS, QuTS hero, QuTScloud | High | Not in CISA | 27 Apr 2025 |
|
CVE-2020-2506
improper access control vulnerability in Helpdesk |
Helpdesk | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2021-28799
Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync) |
HBS 3, HBS 2, HBS 1.3 | Confirmed | In CISA | 31 Mar 2022 |
|
CVE-2020-2509
Command Injection Vulnerability in QTS and QuTS hero |
QTS, QuTS hero | Confirmed | In CISA | 11 Apr 2022 |
|
CVE-2018-19943
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in... |
QTS | Confirmed | In CISA | 24 May 2022 |
|
CVE-2018-19949
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the... |
QTS | Confirmed | In CISA | 24 May 2022 |
|
CVE-2018-19953
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in... |
QTS | Confirmed | In CISA | 24 May 2022 |
|
CVE-2019-7192
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP... |
QNAP NAS devices running Photo Station | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2019-7193
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP... |
QNAP NAS devices | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2019-7194
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP... |
QNAP NAS devices running Photo Station | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2019-7195
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP... |
QNAP NAS devices running Photo Station | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2022-27593
DeadBolt Ransomware |
Photo Station | Confirmed | In CISA | 08 Sep 2022 |
|
CVE-2023-47565
Legacy VioStor NVR |
VioStor NVR | Confirmed | In CISA | 21 Dec 2023 |
|
CVE-2024-27130
QTS, QuTS hero |
QTS, QuTS hero | High | Not in CISA | 21 May 2024 |
Common Vulnerability Classes (CWE)
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 6
- CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 4
- CWE-80 — Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) 2
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
- CWE-287 — Improper Authentication 2
- CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 2
- CWE-20 — Improper Input Validation 2
- CWE-863 — Incorrect Authorization 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology