qnap
27 known vulnerabilities affecting qnap products.
Products
qts 14
quts_hero 11
file_station 6
qumagie 3
hybrid_backup_sync 1
license_center 1
notification_center 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2018-19949 | Act now | 24.4% | 9.8 | ● | If exploited, this command injection vulnerability could allow remote attackers … |
| CVE-2018-19953 | Act now | 23.9% | 6.1 | ● | If exploited, this cross-site scripting vulnerability could allow remote attacke… |
| CVE-2018-19943 | Act now | 17.7% | 8.0 | ● | If exploited, this cross-site scripting vulnerability could allow remote attacke… |
| CVE-2026-22893 | Medium | 1.1% | 7.2 | A command injection vulnerability has been reported to affect several QNAP opera… | |
| CVE-2025-66273 | Medium | 1.1% | 7.2 | A command injection vulnerability has been reported to affect several QNAP opera… | |
| CVE-2025-66279 | Medium | 1.1% | 7.2 | A command injection vulnerability has been reported to affect several QNAP opera… | |
| CVE-2026-24719 | Medium | 1.0% | 7.2 | A command injection vulnerability has been reported to affect several QNAP opera… | |
| CVE-2026-44083 | Medium | 0.5% | 9.8 | An authorization bypass through user-controlled key vulnerability has been repor… | |
| CVE-2026-26241 | Medium | 0.5% | 9.1 | A buffer overflow vulnerability has been reported to affect File Station 5. The … | |
| CVE-2025-66281 | Medium | 0.5% | 7.2 | A NULL pointer dereference vulnerability has been reported to affect several QNA… | |
| CVE-2026-26240 | Medium | 0.4% | 9.1 | A buffer overflow vulnerability has been reported to affect File Station 5. The … | |
| CVE-2025-66280 | Medium | 0.4% | 7.2 | An integer overflow or wraparound vulnerability has been reported to affect seve… | |
| CVE-2026-26239 | Medium | 0.4% | 8.1 | A buffer overflow vulnerability has been reported to affect File Station 5. If a… | |
| CVE-2026-24724 | Medium | 0.3% | 8.1 | An incorrect authorization vulnerability has been reported to affect File Statio… | |
| CVE-2025-62850 | Medium | 0.3% | 7.2 | A NULL pointer dereference vulnerability has been reported to affect several QNA… | |
| CVE-2026-24716 | Medium | 0.3% | 7.2 | A NULL pointer dereference vulnerability has been reported to affect several QNA… | |
| CVE-2026-26236 | Medium | 0.3% | 7.5 | A missing authorization vulnerability has been reported to affect QuMagie. The r… | |
| CVE-2026-26237 | Medium | 0.3% | 7.5 | A missing authorization vulnerability has been reported to affect QuMagie. The r… | |
| CVE-2025-66276 | Medium | 0.3% | 9.8 | QuTS hero is not affected. We have already fixed the vulnerability in the follo… | |
| CVE-2025-62842 | Medium | 0.3% | 7.8 | An external control of file name or path vulnerability has been reported to affe… | |
| CVE-2025-58468 | Medium | 0.2% | 8.8 | A cross-site request forgery (CSRF) vulnerability has been reported to affect No… | |
| CVE-2025-62858 | Low | 0.4% | 6.5 | A buffer overflow vulnerability has been reported to affect several QNAP operati… | |
| CVE-2026-24717 | Low | 0.4% | 6.5 | A path traversal vulnerability has been reported to affect several QNAP operatin… | |
| CVE-2026-22899 | Low | 0.4% | 6.5 | A NULL pointer dereference vulnerability has been reported to affect File Statio… | |
| CVE-2026-24720 | Low | 0.4% | 6.5 | An allocation of resources without limits or throttling vulnerability has been r… | |
| CVE-2025-62851 | Low | 0.3% | 4.4 | A path traversal vulnerability has been reported to affect License Center. If a … | |
| CVE-2026-41539 | Low | 0.2% | 6.1 | A cross-site scripting (XSS) vulnerability has been reported to affect several Q… |