QNAP Systems Inc. Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for QNAP Systems Inc. products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

14

In CISA KEV

8

Beyond CISA KEV

6

Sensor Observed

0

Virtual Patch Available

0

QNAP Systems Inc. KEVs Added by Year

Loading...

14 QNAP Systems Inc. KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2023-50358

QTS, QuTS hero, QuTScloud

High Not in CISA 26 Oct 2025
CVE-2023-45038

Music Station

High Not in CISA 21 Aug 2025
CVE-2020-2507

command injection vulnerability in Helpdesk

High Not in CISA 16 Aug 2025
CVE-2023-47218

QTS, QuTS hero, QuTScloud

High Not in CISA 05 Jun 2025
CVE-2024-21899

QTS, QuTS hero, QuTScloud

High Not in CISA 27 Apr 2025
CVE-2020-2506

improper access control vulnerability in Helpdesk

Confirmed In CISA 25 Mar 2022
CVE-2021-28799

Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)

Confirmed In CISA 31 Mar 2022
CVE-2020-2509

Command Injection Vulnerability in QTS and QuTS hero

Confirmed In CISA 11 Apr 2022
CVE-2018-19943

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in...

Confirmed In CISA 24 May 2022
CVE-2018-19949

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the...

Confirmed In CISA 24 May 2022
CVE-2018-19953

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in...

Confirmed In CISA 24 May 2022
CVE-2022-27593

DeadBolt Ransomware

Confirmed In CISA 08 Sep 2022
CVE-2023-47565

Legacy VioStor NVR

Confirmed In CISA 21 Dec 2023
CVE-2024-27130

QTS, QuTS hero

High Not in CISA 21 May 2024

Common Vulnerability Classes (CWE)

  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 6
  • CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 4
  • CWE-80 — Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) 2
  • CWE-287 — Improper Authentication 2
  • CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 2
  • CWE-120 — Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') 1
  • CWE-610 — Externally Controlled Reference to a Resource in Another Sphere 1
  • CWE-20 — Improper Input Validation 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology