cbcvebase.

Qnap Qts vulnerabilities

283 known vulnerabilities affecting qnap/qts.

Total CVEs
283
CISA KEV
7
actively exploited
Public exploits
10
Exploited in wild
16
Severity breakdown
CRITICAL44HIGH116MEDIUM120LOW3

Vulnerabilities

Page 13 of 15
CVE-2025-52430P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+14 more2026-01-02
CVE-2025-52430 [MEDIUM] CWE-476 CVE-2025-52430: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and lat
nvd
CVE-2025-52431P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+14 more2026-01-02
CVE-2025-52431 [MEDIUM] CWE-476 CVE-2025-52431: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and lat
nvd
CVE-2015-5664P4MEDIUMCVSS 6.1≤ 4.1.42016-07-03
CVE-2015-5664 [MEDIUM] CWE-79 CVE-2015-5664: Cross-site scripting (XSS) vulnerability in File Station in QNAP QTS before 4.2.0 allows remote atta Cross-site scripting (XSS) vulnerability in File Station in QNAP QTS before 4.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2018-0711P4MEDIUMCVSS 6.1v4.3.3.0514v4.3.3.0546+11 more2018-04-30
CVE-2018-0711 [MEDIUM] CWE-79 CVE-2018-0711: Cross-site scripting (XSS) vulnerability in QNAP QTS 4.3.3 build 20180126, QTS 4.3.4 build 20180315, Cross-site scripting (XSS) vulnerability in QNAP QTS 4.3.3 build 20180126, QTS 4.3.4 build 20180315, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.
nvd
CVE-2017-7632P4MEDIUMCVSS 6.1v4.2.6v4.3.32018-03-27
CVE-2017-7632 [MEDIUM] CWE-79 CVE-2017-7632: Cross-site scripting (XSS) vulnerability in File Station of QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 Cross-site scripting (XSS) vulnerability in File Station of QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to inject arbitrary web script or HTML.
nvd
CVE-2025-47213P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+12 more2025-10-03
CVE-2025-47213 [MEDIUM] CWE-476 CVE-2025-47213: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and lat
nvd
CVE-2025-48726P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+12 more2025-10-03
CVE-2025-48726 [MEDIUM] CWE-476 CVE-2025-48726: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and lat
nvd
CVE-2025-48728P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+12 more2025-10-03
CVE-2025-48728 [MEDIUM] CWE-476 CVE-2025-48728: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and lat
nvd
CVE-2025-48729P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+12 more2025-10-03
CVE-2025-48729 [MEDIUM] CWE-476 CVE-2025-48729: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and lat
nvd
CVE-2025-52427P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+12 more2025-10-03
CVE-2025-52427 [MEDIUM] CWE-476 CVE-2025-52427: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and lat
nvd
CVE-2025-47214P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+12 more2025-10-03
CVE-2025-47214 [MEDIUM] CWE-476 CVE-2025-47214: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and lat
nvd
CVE-2025-48727P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+12 more2025-10-03
CVE-2025-48727 [MEDIUM] CWE-476 CVE-2025-48727: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and lat
nvd
CVE-2025-52424P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+12 more2025-10-03
CVE-2025-52424 [MEDIUM] CWE-476 CVE-2025-52424: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and lat
nvd
CVE-2025-52858P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+12 more2025-10-03
CVE-2025-52858 [MEDIUM] CWE-476 CVE-2025-52858: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and lat
nvd
CVE-2025-52862P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+12 more2025-10-03
CVE-2025-52862 [MEDIUM] CWE-476 CVE-2025-52862: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and lat
nvd
CVE-2025-52860P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+12 more2025-10-03
CVE-2025-52860 [MEDIUM] CWE-476 CVE-2025-52860: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and lat
nvd
CVE-2025-52866P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+12 more2025-10-03
CVE-2025-52866 [MEDIUM] CWE-476 CVE-2025-52866: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and lat
nvd
CVE-2025-52428P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+12 more2025-10-03
CVE-2025-52428 [MEDIUM] CWE-476 CVE-2025-52428: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and lat
nvd
CVE-2025-52853P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+12 more2025-10-03
CVE-2025-52853 [MEDIUM] CWE-476 CVE-2025-52853: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and lat
nvd
CVE-2025-52859P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+12 more2025-10-03
CVE-2025-52859 [MEDIUM] CWE-476 CVE-2025-52859: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and lat
nvd
Qnap Qts vulnerabilities | cvebase