QNAP Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for QNAP products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

18

In CISA KEV

12

Beyond CISA KEV

6

Sensor Observed

0

Virtual Patch Available

0

QNAP KEVs Added by Year

Loading...

18 QNAP KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2023-50358

QTS, QuTS hero, QuTScloud

High Not in CISA 26 Oct 2025
CVE-2023-45038

Music Station

High Not in CISA 21 Aug 2025
CVE-2020-2507

command injection vulnerability in Helpdesk

High Not in CISA 16 Aug 2025
CVE-2023-47218

QTS, QuTS hero, QuTScloud

High Not in CISA 05 Jun 2025
CVE-2024-21899

QTS, QuTS hero, QuTScloud

High Not in CISA 27 Apr 2025
CVE-2020-2506

improper access control vulnerability in Helpdesk

Confirmed In CISA 25 Mar 2022
CVE-2021-28799

Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)

Confirmed In CISA 31 Mar 2022
CVE-2020-2509

Command Injection Vulnerability in QTS and QuTS hero

Confirmed In CISA 11 Apr 2022
CVE-2018-19943

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in...

Confirmed In CISA 24 May 2022
CVE-2018-19949

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the...

Confirmed In CISA 24 May 2022
CVE-2018-19953

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in...

Confirmed In CISA 24 May 2022
CVE-2019-7192

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP...

Confirmed In CISA 08 Jun 2022
CVE-2019-7193

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP...

Confirmed In CISA 08 Jun 2022
CVE-2019-7194

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP...

Confirmed In CISA 08 Jun 2022
CVE-2019-7195

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP...

Confirmed In CISA 08 Jun 2022
CVE-2022-27593

DeadBolt Ransomware

Confirmed In CISA 08 Sep 2022
CVE-2023-47565

Legacy VioStor NVR

Confirmed In CISA 21 Dec 2023
CVE-2024-27130

QTS, QuTS hero

High Not in CISA 21 May 2024

Common Vulnerability Classes (CWE)

  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 6
  • CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 4
  • CWE-80 — Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) 2
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
  • CWE-287 — Improper Authentication 2
  • CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 2
  • CWE-20 — Improper Input Validation 2
  • CWE-863 — Incorrect Authorization 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology