Qnap Qts vulnerabilities
283 known vulnerabilities affecting qnap/qts.
Total CVEs
283
CISA KEV
7
actively exploited
Public exploits
10
Exploited in wild
16
Severity breakdown
CRITICAL44HIGH116MEDIUM120LOW3
Vulnerabilities
Page 14 of 15
CVE-2025-52857P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+12 more2025-10-03
CVE-2025-52857 [MEDIUM] CWE-476 CVE-2025-52857: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.6.3195 build 20250715 and lat
nvd
CVE-2025-52433P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+12 more2025-10-03
CVE-2025-52433 [MEDIUM] CWE-476 CVE-2025-52433: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.6.3195 build 20250715 and lat
nvd
CVE-2015-5664P4MEDIUMCVSS 6.1≤ 4.1.42016-07-03
CVE-2015-5664 [MEDIUM] CWE-79 CVE-2015-5664: Cross-site scripting (XSS) vulnerability in File Station in QNAP QTS before 4.2.0 allows remote atta
Cross-site scripting (XSS) vulnerability in File Station in QNAP QTS before 4.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2018-0711P4MEDIUMCVSS 6.1v4.3.3.0514v4.3.3.0546+11 more2018-04-30
CVE-2018-0711 [MEDIUM] CWE-79 CVE-2018-0711: Cross-site scripting (XSS) vulnerability in QNAP QTS 4.3.3 build 20180126, QTS 4.3.4 build 20180315,
Cross-site scripting (XSS) vulnerability in QNAP QTS 4.3.3 build 20180126, QTS 4.3.4 build 20180315, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.
nvd
CVE-2017-7632P4MEDIUMCVSS 6.1v4.2.6v4.3.32018-03-27
CVE-2017-7632 [MEDIUM] CWE-79 CVE-2017-7632: Cross-site scripting (XSS) vulnerability in File Station of QNAP QTS 4.2.6 build 20171026, QTS 4.3.3
Cross-site scripting (XSS) vulnerability in File Station of QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to inject arbitrary web script or HTML.
nvd
CVE-2025-53590P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+14 more2026-01-02
CVE-2025-53590 [MEDIUM] CWE-476 CVE-2025-53590: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following version:
QTS 5.2.7.3256 build 20250913 and late
nvd
CVE-2017-7631P4MEDIUMCVSS 6.1v4.2.6v4.3.32018-03-27
CVE-2017-7631 [MEDIUM] CWE-79 CVE-2017-7631: Cross-site scripting (XSS) vulnerability in the share link function of File Station of QNAP 4.2.6 bu
Cross-site scripting (XSS) vulnerability in the share link function of File Station of QNAP 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to inject arbitrary web script or HTML.
nvd
CVE-2018-0716P4MEDIUMCVSS 6.1v4.2.6v4.3.3+2 more2018-11-30
CVE-2018-0716 [MEDIUM] CWE-79 CVE-2018-0716: Cross-site scripting vulnerability in QTS 4.2.6 build 20180711, QTS 4.3.3: Qsync Central 3.0.2, QTS
Cross-site scripting vulnerability in QTS 4.2.6 build 20180711, QTS 4.3.3: Qsync Central 3.0.2, QTS 4.3.4: Qsync Central 3.0.3, QTS 4.3.5: Qsync Central 3.0.4 and earlier versions could allow remote attackers to inject Javascript code in the compromised application.
nvd
CVE-2017-13072P4MEDIUMCVSS 6.1v4.2.6v4.3.3+1 more2018-06-21
CVE-2017-13072 [MEDIUM] CWE-79 CVE-2017-13072: Cross-site scripting (XSS) vulnerability in App Center in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 b
Cross-site scripting (XSS) vulnerability in App Center in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20171213, QTS 4.3.4 build 20171223, and their earlier versions could allow remote attackers to inject Javascript code.
nvd
CVE-2024-37048P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+5 more2024-11-22
CVE-2024-37048 [MEDIUM] CWE-476 CVE-2024-37048: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.1.2930 build 20241025 an
nvd
CVE-2023-32970P4MEDIUMCVSS 4.9≥ 4.5.1, < 4.5.4.2467≥ 5.0.0.1716, < 5.0.1.2425+1 more2023-10-13
CVE-2023-32970 [MEDIUM] CWE-476 CVE-2023-32970: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to launch a denial-of-service (DoS) attack via a network.
QES is not affected.
We have already fixed the vulnerability in the following versions:
QuTS hero h5.0.1.2515
nvd
CVE-2023-45028P4MEDIUMCVSS 4.9v5.1.0.2348v5.1.0.2399+8 more2024-02-02
CVE-2023-45028 [MEDIUM] CWE-400 CVE-2023-45028: An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operatin
An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to launch a denial-of-service (DoS) attack via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.5.2645 build 20240116 and
nvd
CVE-2023-39301P4MEDIUMCVSS 4.3fixed in 5.1.1.2491fixed in 5.0.1.25142023-11-03
CVE-2023-39301 [MEDIUM] CWE-918 CVE-2023-39301: A server-side request forgery (SSRF) vulnerability has been reported to affect several QNAP operatin
A server-side request forgery (SSRF) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to read application data via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2514 build 20230906 and later
QTS 5.1.1.2491 build
nvd
CVE-2024-37042P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+5 more2024-11-22
CVE-2024-37042 [MEDIUM] CWE-476 CVE-2024-37042: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.1.2930 build 20241025 an
nvd
CVE-2024-37045P4MEDIUMCVSS 4.9v5.2.0.2737v5.2.0.2744+5 more2024-11-22
CVE-2024-37045 [MEDIUM] CWE-476 CVE-2024-37045: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.1.2930 build 20241025 an
nvd
CVE-2023-41274P4MEDIUMCVSS 4.9v5.1.0.2348v5.1.0.2399+5 more2024-02-02
CVE-2023-41274 [MEDIUM] CWE-476 CVE-2023-41274: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to launch a denial-of-service (DoS) attack via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.2.2533 build 20230926 and later
QuT
nvd
CVE-2023-32969P4MEDIUMCVSS 4.8≥ 5.1.0, < 5.1.4.2596v5.1.4.25962024-03-08
CVE-2023-32969 [MEDIUM] CWE-79 CVE-2023-32969: A cross-site scripting (XSS) vulnerability has been reported to affect Network & Virtual Switch. If
A cross-site scripting (XSS) vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network.
We have already fixed the vulnerability in the following versions:
QuTScloud c5.1.5.2651 and later
QTS 5.1.4.2596 build 20231128 and later
QuT
nvd
CVE-2023-50366P4MEDIUMCVSS 4.8v5.1.0.2348v5.1.0.2399+9 more2024-09-06
CVE-2023-50366 [MEDIUM] CWE-79 CVE-2023-50366: A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.6.2722 build 20240402 and later
QuTS hero h5.1.6.273
nvd
CVE-2019-7197P4MEDIUMCVSS 4.8v4.2.6v4.3.3+3 more2019-12-04
CVE-2019-7197 [MEDIUM] CWE-79 CVE-2019-7197: A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of Q
A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS. If exploited, this vulnerability may allow an attacker to inject and execute scripts on the administrator console. To fix this vulnerability, QNAP recommend updating QTS to the latest version.
nvd
CVE-2024-32765P4MEDIUMCVSS 4.2≥ 5.1.0, < 5.1.8.28232024-08-12
CVE-2024-32765 [MEDIUM] CWE-291 CVE-2024-32765: A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerabilit
A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow local authenticated administrators to gain access to and execute certain functions via unspecified vectors.
We have already fixed the vulnerability in the following versions:
QTS 5.1.8.2823 build 20240712 and later
QuTS hero h5.1.8.2823
nvd