cbcvebase.

Qnap Qts vulnerabilities

283 known vulnerabilities affecting qnap/qts.

Total CVEs
283
CISA KEV
7
actively exploited
Public exploits
10
Exploited in wild
16
Severity breakdown
CRITICAL44HIGH116MEDIUM120LOW3

Vulnerabilities

Page 4 of 15
CVE-2024-27127P3HIGHCVSS 8.8v5.1.0.2348v5.1.0.2399+10 more2024-05-21
CVE-2024-27127 [HIGH] CWE-415 CVE-2024-27127: A double free vulnerability has been reported to affect several QNAP operating system versions. If e A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute arbitrary code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero h5.1.7.2770 build 20240520 and late
nvd
CVE-2024-27129P3HIGHCVSS 8.8v5.1.0.2348v5.1.0.2399+10 more2024-05-21
CVE-2024-27129 [HIGH] CWE-120 CVE-2024-27129: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero h5.1.7.2770 bui
nvd
CVE-2024-27128P3HIGHCVSS 8.8v5.1.0.2348v5.1.0.2399+10 more2024-05-21
CVE-2024-27128 [HIGH] CWE-120 CVE-2024-27128: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero h5.1.7.2770 bui
nvd
CVE-2024-50397P3HIGHCVSS 8.8v5.2.0.2737v5.2.0.2744+5 more2024-11-22
CVE-2024-50397 [HIGH] CWE-134 CVE-2024-50397: A use of externally-controlled format string vulnerability has been reported to affect several QNAP A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025
nvd
CVE-2023-23363P3CRITICALCVSS 9.8≥ 4.3.3, < 4.3.3.2420≥ 4.3.4, < 4.3.4.245+1 more2023-09-22
CVE-2023-23363 [CRITICAL] CWE-120 CVE-2023-23363: A buffer copy without checking size of input vulnerability has been reported to affect QNAP operatin A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating system. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 4.3.6.2441 build 20230621 and later QTS 4.3.3.2420 build 20230621
nvd
CVE-2023-47568P3HIGHCVSS 8.8v4.5.4.1715v4.5.4.1723+20 more2024-02-02
CVE-2023-47568 [HIGH] CWE-89 CVE-2023-47568: A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.5.2645 build 20240116 and later QTS 4.5.4.2627 build 20231225 and later QuTS
nvd
CVE-2023-51367P3HIGHCVSS 8.8v5.1.0.2348v5.1.0.2399+9 more2024-09-06
CVE-2023-51367 [HIGH] CWE-120 CVE-2023-51367: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 build 20240414 a
nvd
CVE-2019-7183P3CRITICALCVSS 9.8v4.2.6v4.3.3.0868+23 more2019-12-05
CVE-2019-7183 [CRITICAL] CWE-59 CVE-2019-7183: This improper link resolution vulnerability allows remote attackers to access system files. To fix t This improper link resolution vulnerability allows remote attackers to access system files. To fix this vulnerability, QNAP recommend updating QTS to their latest versions.
nvd
CVE-2026-22893P3HIGHCVSS 7.2≥ 5.2.0.2737, < 5.2.9.34102026-06-10
CVE-2026-22893 [HIGH] CWE-78 CVE-2026-22893: A command injection vulnerability has been reported to affect several QNAP operating system versions A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.341
nvd
CVE-2025-66279P3HIGHCVSS 7.2≥ 5.2.0.2737, < 5.2.9.34102026-06-10
CVE-2025-66279 [HIGH] CWE-78 CVE-2025-66279: A command injection vulnerability has been reported to affect several QNAP operating system versions A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.341
nvd
CVE-2025-66273P3HIGHCVSS 7.2≥ 5.2.0.2737, < 5.2.9.34102026-06-10
CVE-2025-66273 [HIGH] CWE-78 CVE-2025-66273: A command injection vulnerability has been reported to affect several QNAP operating system versions A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.341
nvd
CVE-2025-66276P3CRITICALCVSS 9.8≥ 4.3.0, < 5.2.7.32562026-06-10
CVE-2025-66276 [CRITICAL] CVE-2025-66276: QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5. QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later
nvd
CVE-2021-28816P3HIGHCVSS 8.8fixed in 4.3.3.1693≥ 4.3.4, < 4.3.6.1750+2 more2021-09-10
CVE-2021-28816 [HIGH] CWE-787 CVE-2021-28816: A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QTS, QuTScloud, QuTS hero: QTS 4.5.4.1715 build 20210630 and later QTS 5.0.0.1716 build 20210
nvd
CVE-2025-47212P3HIGHCVSS 7.2v5.2.0.2737v5.2.0.2744+12 more2025-10-03
CVE-2025-47212 [HIGH] CWE-78 CVE-2025-47212: A command injection vulnerability has been reported to affect several QNAP operating system versions A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and later QuTS hero h5.2.6.319
nvd
CVE-2026-24719P3HIGHCVSS 7.2≥ 5.2.0.2737, < 5.2.9.34922026-06-10
CVE-2026-24719 [HIGH] CWE-78 CVE-2026-24719: A command injection vulnerability has been reported to affect several QNAP operating system versions A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.349
nvd
CVE-2018-19945P3CRITICALCVSS 9.1≥ 4.3.4, < 4.3.4.0899≥ 4.3.5, < 4.3.6.08952020-12-31
CVE-2018-19945 [CRITICAL] CWE-20 CVE-2018-19945: A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitations of a pathname to a restricted directory, this vulnerability allows for renaming arbitrary files on the target system, if exploited. QNAP have already fixed this vulnerability in the following versions: QTS 4.3.6.0895 build 2019
nvd
CVE-2015-6003P3CRITICALCVSS 9.3≤ 4.1.4≤ 4.2.02015-10-16
CVE-2015-6003 [CRITICAL] CWE-22 CVE-2015-6003: Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 bui Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.
nvd
CVE-2020-2490P3HIGHCVSS 7.2fixed in 4.4.3.14212020-11-16
CVE-2020-2490 [HIGH] CWE-77 CVE-2020-2490: If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.
nvd
CVE-2024-14026P3HIGHCVSS 7.8v5.1.0.2348v5.1.0.2399+21 more2026-03-11
CVE-2024-14026 [HIGH] CWE-78 CVE-2024-14026: A command injection vulnerability has been reported to affect several QNAP operating system versions A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and
nvd
CVE-2025-48725P3HIGHCVSS 8.1v5.2.0.2737v5.2.0.2744+17 more2026-02-11
CVE-2025-48725 [HIGH] CWE-120 CVE-2025-48725: A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: QuTS hero h5.3.2.3354 build 20251225 and later
nvd
Qnap Qts vulnerabilities | cvebase