← Back

Qnap

qnap

635 CVEs • 143 products

Products (143)

Click to collapse
Toggle
Qts
qts
Quts Hero
quts_hero
Qutscloud
qutscloud
Qsync Central
qsync_central
File Station
file_station
Photo Station
photo_station
Video Station
video_station
Music Station
music_station
Qumagie
qumagie
Qurouter
qurouter
Helpdesk
helpdesk
Qvr
qvr
Qulog Center
qulog_center
Q'center
q'center
Qvr Pro
qvr_pro
Qunetswitch
qunetswitch
Qvr Elite
qvr_elite
Qvr Guard
qvr_guard
Qes
qes
Qcalagent
qcalagent
Qvpn
qvpn
Qufirewall
qufirewall
Nas
nas
Iartist Lite
iartist_lite
Myqnapcloud
myqnapcloud
Qss
qss
Qusbcam2
qusbcam2
Qmailagent
qmailagent
Kazoo Server
kazoo_server
Ts 469u
ts-469u
Ts Ec1679u Rp
ts-ec1679u-rp
Ts 459u
ts-459u
Ss 839
ss-839
Sinage Station
sinage_station
Qts Helpdesk
qts_helpdesk
Qsync
qsync
Qfinder Pro
qfinder_pro
Roon Server
roon_server
Image2pdf
image2pdf
Ragic Cloud Db
ragic_cloud_db
Qfile
qfile
Qvr Pro Client
qvr_pro_client
Qvr Firmware
qvr_firmware
Ai Core
ai_core

CVEs (635)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qnap
1Qulog Center
Jun 17, 2026
Dec 19, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to bypass s...Show more
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QuLog Center 1.5.0.738 ( 2023/03/06 ) and later QuLog Center 1.4.1.691 ( 2023/03/01 ) and later QuLog Center 1.3.1.645 ( 2023/02/22 ) and laterShow less
1Qnap
1Qufirewall
Jun 17, 2026
Dec 19, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary...Show more
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QuFirewall 2.3.3 ( 2023/03/27 ) and later and laterShow less
1Qnap
1Qulog Center
Jun 17, 2026
Dec 19, 2024
N/A· v4
8.7 HIGH· v3
N/A· v2
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to bypass security m...Show more
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QuLog Center 1.5.0.738 ( 2023/03/06 ) and later QuLog Center 1.4.1.691 ( 2023/03/01 ) and later QuLog Center 1.3.1.645 ( 2023/02/22 ) and laterShow less
1Qnap
3Qts
Quts HeroQutscloud
Jun 17, 2026
Dec 19, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to launch a denial-of-service (DoS) atta...Show more
An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2277 and later QTS 4.5.4.2280 build 20230112 and later QuTS hero h5.0.1.2277 build 20230112 and later QuTS hero h4.5.4.2374 build 20230417 and later QuTScloud c5.0.1.2374 and laterShow less
1Qnap
1Qvpn
Jun 17, 2026
Dec 19, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
An insecure library loading vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local attackers who have gained user access to execute unauthorized code or commands....Show more
An insecure library loading vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local attackers who have gained user access to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: QVPN Windows 2.0.0.1316 and later QVPN Windows 2.0.0.1310 and laterShow less
1Qnap
2Qts
Quts Hero
Jun 17, 2026
Dec 6, 2024
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to u...Show more
A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QTS 5.2.0.2802 build 20240620 and later QuTS hero h5.1.8.2823 build 20240712 and later QuTS hero h5.2.0.2802 build 20240620 and laterShow less
1Qnap
1Qsync Central
Jun 17, 2026
Dec 6, 2024
6.8 MEDIUM· v4
8.8 HIGH· v3
N/A· v2
A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We...Show more
A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.16_20240819 ( 2024/08/19 ) and laterShow less
1Qnap
2Qts
Quts Hero
Jun 17, 2026
Dec 6, 2024
2.1 LOW· v4
7.2 HIGH· v3
N/A· v2
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator ac...Show more
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.2.2.2952 build 20241116 and laterShow less
1Qnap
2Qts
Quts Hero
Jun 17, 2026
Dec 6, 2024
2.1 LOW· v4
7.2 HIGH· v3
N/A· v2
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator ac...Show more
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.1.9.2954 build 20241120 and later QuTS hero h5.2.2.2952 build 20241116 and laterShow less
1Qnap
2Qts
Quts Hero
Jun 17, 2026
Dec 6, 2024
8.7 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the...Show more
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.1.9.2954 build 20241120 and later QuTS hero h5.2.2.2952 build 20241116 and laterShow less
1Qnap
1Qurouter
Jun 17, 2026
Dec 6, 2024
9.5 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability has been reported to affect QuRouter. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version...Show more
A SQL injection vulnerability has been reported to affect QuRouter. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and laterShow less
1Qnap
1Hybrid Backup Sync
Jun 17, 2026
Dec 6, 2024
9.5 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in th...Show more
An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.1.673 and laterShow less
1Qnap
1Smb Service
Jun 17, 2026
Dec 6, 2024
10.0 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerab...Show more
A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: SMB Service 4.15.002 and later SMB Service h4.15.002 and laterShow less
1Qnap
2Qts
Quts Hero
Jun 17, 2026
Dec 6, 2024
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify app...Show more
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.1.9.2954 build 20241120 and later QuTS hero h5.2.2.2952 build 20241116 and laterShow less
1Qnap
2Qts
Quts Hero
Jun 17, 2026
Dec 6, 2024
5.3 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify app...Show more
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.1.9.2954 build 20241120 and later QuTS hero h5.2.2.2952 build 20241116 and laterShow less
1Qnap
2Qts
Quts Hero
Jun 17, 2026
Dec 6, 2024
2.3 LOW· v4
5.3 MEDIUM· v3
N/A· v2
An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to run the system into un...Show more
An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to run the system into unexpected state. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.1.9.2954 build 20241120 and later QuTS hero h5.2.2.2952 build 20241116 and laterShow less
1Qnap
2Qts
Quts Hero
Jun 17, 2026
Dec 6, 2024
7.3 HIGH· v4
7.5 HIGH· v3
N/A· v2
An improper certificate validation vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow attackers with local network access to compromise the secur...Show more
An improper certificate validation vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow attackers with local network access to compromise the security of the system. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.1.9.2954 build 20241120 and later QuTS hero h5.2.2.2952 build 20241116 and laterShow less
1Qnap
1License Center
Jun 17, 2026
Dec 6, 2024
7.7 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
A command injection vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the fo...Show more
A command injection vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following version: License Center 1.9.43 and laterShow less
1Qnap
2Qts
Quts Hero
Jun 17, 2026
Dec 6, 2024
5.3 MEDIUM· v4
9.1 CRITICAL· v3
N/A· v2
An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have...Show more
An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.1.9.2954 build 20241120 and later QuTS hero h5.2.2.2952 build 20241116 and laterShow less
1Qnap
2Qts
Quts Hero
Jun 17, 2026
Nov 22, 2024
2.1 LOW· v4
7.2 HIGH· v3
N/A· v2
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator ac...Show more
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and laterShow less