Qnap Qts vulnerabilities
283 known vulnerabilities affecting qnap/qts.
Total CVEs
283
CISA KEV
7
actively exploited
Public exploits
10
Exploited in wild
16
Severity breakdown
CRITICAL44HIGH116MEDIUM120LOW3
Vulnerabilities
Page 10 of 15
CVE-2025-47208P3MEDIUMCVSS 6.5v5.2.0.2737v5.2.0.2744+14 more2026-01-02
CVE-2025-47208 [MEDIUM] CWE-770 CVE-2025-47208: An allocation of resources without limits or throttling vulnerability has been reported to affect se
An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource.
We have already fixed the vulnerab
nvd
CVE-2023-32967P3MEDIUMCVSS 6.5v4.5.4.1715v4.5.4.1723+10 more2024-02-02
CVE-2023-32967 [MEDIUM] CWE-285 CVE-2023-32967: An incorrect authorization vulnerability has been reported to affect several QNAP operating system v
An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended access restrictions via a network.
QTS 5.x, QuTS hero are not affected.
We have already fixed the vulnerability in the following versions:
QuTScloud c5.1.5.26
nvd
CVE-2018-14747P3HIGHCVSS 7.5v4.2.6v4.3.3+2 more2018-11-28
CVE-2018-14747 [HIGH] CWE-476 CVE-2018-14747: NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.
NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to crash the NAS media server.
nvd
CVE-2025-30265P3MEDIUMCVSS 6.5v5.2.0.2737v5.2.0.2744+11 more2025-08-29
CVE-2025-30265 [MEDIUM] CWE-120 CVE-2025-30265: A buffer overflow vulnerability has been reported to affect several QNAP operating system versions.
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the following versions:
QTS 5.2.5.3145 build 20250526 and later
QuTS hero h5.2.5.3138 bu
nvd
CVE-2025-53592P3MEDIUMCVSS 6.5v5.2.0.2737v5.2.0.2744+14 more2026-01-02
CVE-2025-53592 [MEDIUM] CWE-476 CVE-2025-53592: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3256 build 20250913 and later
QuTS he
nvd
CVE-2025-44013P3MEDIUMCVSS 6.5v5.2.0.2737v5.2.0.2744+14 more2026-01-02
CVE-2025-44013 [MEDIUM] CWE-476 CVE-2025-44013: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.6.3195 build 20250715 and later
QuTS he
nvd
CVE-2017-7629P3HIGHCVSS 7.5≤ 4.2.62017-06-15
CVE-2017-7629 [HIGH] CWE-640 CVE-2017-7629: QNAP QTS before 4.2.6 build 20170517 has a flaw in the change password function.
QNAP QTS before 4.2.6 build 20170517 has a flaw in the change password function.
nvd
CVE-2024-53692P3MEDIUMCVSS 4.7v5.2.0.2737v5.2.0.2744+7 more2025-03-07
CVE-2024-53692 [MEDIUM] CWE-77 CVE-2024-53692: A command injection vulnerability has been reported to affect several QNAP operating system versions
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands.
We have already fixed the vulnerability in the following versions:
QTS 5.2.3.3006 build 20250108 and later
QuTS hero h5.
nvd
CVE-2025-29882P3MEDIUMCVSS 6.5v5.2.0.2737v5.2.0.2744+11 more2025-08-29
CVE-2025-29882 [MEDIUM] CWE-476 CVE-2025-29882: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.5.3145 build 20250526 and later
QuTS he
nvd
CVE-2025-30267P3MEDIUMCVSS 6.5v5.2.0.2737v5.2.0.2744+11 more2025-08-29
CVE-2025-30267 [MEDIUM] CWE-476 CVE-2025-30267: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.5.3145 build 20250526 and later
QuTS he
nvd
CVE-2025-30268P3MEDIUMCVSS 6.5v5.2.0.2737v5.2.0.2744+11 more2025-08-29
CVE-2025-30268 [MEDIUM] CWE-476 CVE-2025-30268: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.5.3145 build 20250526 and later
QuTS he
nvd
CVE-2023-51368P4MEDIUMCVSS 6.5v5.1.0.2348v5.1.0.2399+9 more2024-09-06
CVE-2023-51368 [MEDIUM] CWE-476 CVE-2023-51368: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to launch a denial-of-service (DoS) attack via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.6.2722 build 20240402 and later
QuTS hero h5.1.6.2734 buil
nvd
CVE-2025-30274P4MEDIUMCVSS 6.5v5.2.0.2737v5.2.0.2744+11 more2025-08-29
CVE-2025-30274 [MEDIUM] CWE-476 CVE-2025-30274: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.5.3145 build 20250526 and later
QuTS hero h5.2.5.3138 build 20250519 and later
nvd
CVE-2025-30272P4MEDIUMCVSS 6.5v5.2.0.2737v5.2.0.2744+11 more2025-08-29
CVE-2025-30272 [MEDIUM] CWE-476 CVE-2025-30272: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.5.3145 build 20250526 and later
QuTS hero h5.2.5.3138 build 20250519 and later
nvd
CVE-2025-59380P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+16 more2026-01-02
CVE-2025-59380 [MEDIUM] CWE-22 CVE-2025-59380: A path traversal vulnerability has been reported to affect several QNAP operating system versions. I
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data.
We have already fixed the vulnerability in the following versions:
QTS 5.2.8.3332 build 20251128 and l
nvd
CVE-2024-56805P4MEDIUMCVSS 5.4v5.2.0.2737v5.2.0.2744+9 more2025-06-06
CVE-2024-56805 [MEDIUM] CWE-120 CVE-2024-56805: A buffer overflow vulnerability has been reported to affect several QNAP operating system versions.
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to modify memory or crash processes.
We have already fixed the vulnerability in the following versions:
QTS 5.2.4.3079 build 20250321 and later
QuTS hero h5.2.4.3
nvd
CVE-2025-47211P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+12 more2025-10-03
CVE-2025-47211 [MEDIUM] CWE-22 CVE-2025-47211: A path traversal vulnerability has been reported to affect several QNAP operating system versions. I
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data.
We have already fixed the vulnerability in the following versions:
QTS 5.2.6.3195 build 20250715 and l
nvd
CVE-2025-59381P4MEDIUMCVSS 4.9v5.2.0.2737-build_20240417v5.2.0.2744-build_20240424+16 more2026-01-02
CVE-2025-59381 [MEDIUM] CWE-22 CVE-2025-59381: A path traversal vulnerability has been reported to affect several QNAP operating system versions. I
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data.
We have already fixed the vulnerability in the following versions:
QTS 5.2.8.3332 build 20251128 and l
nvd
CVE-2024-21906P4MEDIUMCVSS 4.7v5.1.0.2348v5.1.0.2399+11 more2024-09-06
CVE-2024-21906 [MEDIUM] CWE-78 CVE-2024-21906: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.8.2823 build 20240712 and later
QuTS hero h5.1.8.2823 build 20
nvd
CVE-2024-21903P4MEDIUMCVSS 4.7v5.1.0.2348v5.1.0.2399+9 more2024-09-06
CVE-2024-21903 [MEDIUM] CWE-77 CVE-2024-21903: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.6.2722 build 20240402 and later
QuTS hero h5.1.6.2734 build 20
nvd