QNAP Systems Inc. Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for QNAP Systems Inc. products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
14
In CISA KEV
8
Beyond CISA KEV
6
Sensor Observed
0
Virtual Patch Available
0
QNAP Systems Inc. KEVs Added by Year
14 QNAP Systems Inc. KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2023-50358
QTS, QuTS hero, QuTScloud |
QTS, QuTS hero, QuTScloud | High | Not in CISA | 26 Oct 2025 |
|
CVE-2023-45038
Music Station |
Music Station | High | Not in CISA | 21 Aug 2025 |
|
CVE-2020-2507
command injection vulnerability in Helpdesk |
Helpdesk | High | Not in CISA | 16 Aug 2025 |
|
CVE-2023-47218
QTS, QuTS hero, QuTScloud |
QTS, QuTS hero, QuTScloud | High | Not in CISA | 05 Jun 2025 |
|
CVE-2024-21899
QTS, QuTS hero, QuTScloud |
QTS, QuTS hero, QuTScloud | High | Not in CISA | 27 Apr 2025 |
|
CVE-2020-2506
improper access control vulnerability in Helpdesk |
Helpdesk | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2021-28799
Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync) |
HBS 3, HBS 2, HBS 1.3 | Confirmed | In CISA | 31 Mar 2022 |
|
CVE-2020-2509
Command Injection Vulnerability in QTS and QuTS hero |
QTS, QuTS hero | Confirmed | In CISA | 11 Apr 2022 |
|
CVE-2018-19943
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in... |
QTS | Confirmed | In CISA | 24 May 2022 |
|
CVE-2018-19949
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the... |
QTS | Confirmed | In CISA | 24 May 2022 |
|
CVE-2018-19953
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in... |
QTS | Confirmed | In CISA | 24 May 2022 |
|
CVE-2022-27593
DeadBolt Ransomware |
Photo Station | Confirmed | In CISA | 08 Sep 2022 |
|
CVE-2023-47565
Legacy VioStor NVR |
VioStor NVR | Confirmed | In CISA | 21 Dec 2023 |
|
CVE-2024-27130
QTS, QuTS hero |
QTS, QuTS hero | High | Not in CISA | 21 May 2024 |
Common Vulnerability Classes (CWE)
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 6
- CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 4
- CWE-80 — Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) 2
- CWE-287 — Improper Authentication 2
- CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 2
- CWE-120 — Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') 1
- CWE-610 — Externally Controlled Reference to a Resource in Another Sphere 1
- CWE-20 — Improper Input Validation 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology