cbcvebase.

Qnap Qts vulnerabilities

283 known vulnerabilities affecting qnap/qts.

Total CVEs
283
CISA KEV
7
actively exploited
Public exploits
10
Exploited in wild
16
Severity breakdown
CRITICAL44HIGH116MEDIUM120LOW3

Vulnerabilities

Page 12 of 15
CVE-2023-45026P4MEDIUMCVSS 4.9v5.1.0.2348v5.1.0.2399+8 more2024-02-02
CVE-2023-45026 [MEDIUM] CWE-22 CVE-2023-45026: A path traversal vulnerability has been reported to affect several QNAP operating system versions. I A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.5.2645 build 20240116
nvd
CVE-2025-57705P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+14 more2026-01-02
CVE-2025-57705 [MEDIUM] CWE-770 CVE-2025-57705: An allocation of resources without limits or throttling vulnerability has been reported to affect se An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed th
nvd
CVE-2018-19942P4MEDIUMCVSS 6.1fixed in 4.2.6≥ 4.3.5, < 4.3.6+85 more2021-04-16
CVE-2018-19942 [MEDIUM] CWE-79 CVE-2018-19942: A cross-site scripting (XSS) vulnerability has been reported to affect earlier versions of File Stat A cross-site scripting (XSS) vulnerability has been reported to affect earlier versions of File Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 build 20210202 (and later) QTS 4.5.1.1456 build 20201015 (and later) QTS 4.3.6.14
nvd
CVE-2021-44053P4MEDIUMCVSS 6.1≥ 5.0.0.1716, < 5.0.0.1986≥ 4.3.3.0174, < 4.3.3.1945+4 more2022-05-05
CVE-2021-44053 [MEDIUM] CWE-79 CVE-2021-44053: A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QTS, QuTS A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QTS, QuTS hero and QuTScloud: QTS 4.5.4.1991 build 20220329 and later QTS 5.0.
nvd
CVE-2021-38674P4MEDIUMCVSS 6.1fixed in 4.5.4.17872022-01-07
CVE-2021-38674 [MEDIUM] CWE-79 CVE-2021-38674: A cross-site scripting (XSS) vulnerability has been reported to affect QTS, QuTS hero and QuTScloud. A cross-site scripting (XSS) vulnerability has been reported to affect QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QTS, QuTS hero and QuTScloud: QuTS hero h4.5.4.1771 build 20210825 and later QTS 4.5.4.1787 build
nvd
CVE-2021-44054P4MEDIUMCVSS 6.1≥ 5.0.0.1716, < 5.0.0.1986≥ 4.3.3.0174, < 4.3.3.1945+4 more2022-05-05
CVE-2021-44054 [MEDIUM] CWE-601 CVE-2021-44054: An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows attackers to redirect users to an untrusted page that contains malware. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero and QTS: QuTScloud c5.0.1.1949 and later
nvd
CVE-2025-58466P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+17 more2026-02-11
CVE-2025-58466 [MEDIUM] CWE-457 CVE-2025-58466: A use of uninitialized variable vulnerability has been reported to affect several QNAP operating sys A use of uninitialized variable vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to denial of service conditions, or modify control flow in unexpected ways. We have already fixed the vulnerability in the following versions:
nvd
CVE-2024-53696P4MEDIUMCVSS 4.9≥ 4.5.1, < 4.5.4.29572025-03-07
CVE-2024-53696 [MEDIUM] CWE-918 CVE-2024-53696: A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If expl A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read application data. We have already fixed the vulnerability in the following versions: QuLog Center 1.7.0.829 ( 2024/10/01 ) and later QuLog Center 1.8.0
nvd
CVE-2020-2495P4MEDIUMCVSS 6.1fixed in 4.5.1.1456fixed in 4.4.3.1354+4 more2020-12-10
CVE-2020-2495 [MEDIUM] CWE-79 CVE-2020-2495: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicio If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later QTS 4.3.
nvd
CVE-2020-2496P4MEDIUMCVSS 6.1fixed in 4.5.1.1456fixed in 4.4.3.1354+4 more2020-12-10
CVE-2020-2496 [MEDIUM] CWE-79 CVE-2020-2496: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicio If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later QTS 4.3.
nvd
CVE-2020-2497P4MEDIUMCVSS 6.1fixed in 4.5.1.1456fixed in 4.4.3.1354+4 more2020-12-10
CVE-2020-2497 [MEDIUM] CWE-79 CVE-2020-2497: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicio If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in System Connection Logs. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and late
nvd
CVE-2020-2498P4MEDIUMCVSS 6.1fixed in 4.5.1.1456fixed in 4.4.3.1354+4 more2020-12-10
CVE-2020-2498 [MEDIUM] CWE-79 CVE-2020-2498: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicio If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in certificate configuration. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and l
nvd
CVE-2017-7630P4MEDIUMCVSS 5.3v4.2.6v4.3.32018-03-27
CVE-2017-7630 [MEDIUM] CWE-200 CVE-2017-7630: QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtai QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensitive information (firmware version and running services) via a request to sysinfoReq.cgi.
nvd
CVE-2025-47205P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+16 more2026-02-11
CVE-2025-47205 [MEDIUM] CWE-476 CVE-2025-47205: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3332 build 20251128 and lat
nvd
CVE-2025-52426P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+14 more2026-01-02
CVE-2025-52426 [MEDIUM] CWE-476 CVE-2025-52426: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and lat
nvd
CVE-2025-53414P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+14 more2026-01-02
CVE-2025-53414 [MEDIUM] CWE-476 CVE-2025-53414: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and lat
nvd
CVE-2025-53596P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+14 more2026-01-02
CVE-2025-53596 [MEDIUM] CWE-476 CVE-2025-53596: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and lat
nvd
CVE-2025-53589P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+14 more2026-01-02
CVE-2025-53589 [MEDIUM] CWE-476 CVE-2025-53589: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and lat
nvd
CVE-2025-53405P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+14 more2026-01-02
CVE-2025-53405 [MEDIUM] CWE-476 CVE-2025-53405: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and lat
nvd
CVE-2025-52430P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+14 more2026-01-02
CVE-2025-52430 [MEDIUM] CWE-476 CVE-2025-52430: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and lat
nvd