← Back

Qnap

qnap

635 CVEs • 143 products

Products (143)

Click to collapse
Toggle
Qts
qts
Quts Hero
quts_hero
Qutscloud
qutscloud
Qsync Central
qsync_central
File Station
file_station
Photo Station
photo_station
Video Station
video_station
Music Station
music_station
Qumagie
qumagie
Qurouter
qurouter
Helpdesk
helpdesk
Qvr
qvr
Qulog Center
qulog_center
Q'center
q'center
Qvr Pro
qvr_pro
Qunetswitch
qunetswitch
Qvr Elite
qvr_elite
Qvr Guard
qvr_guard
Qes
qes
Qcalagent
qcalagent
Qvpn
qvpn
Qufirewall
qufirewall
Nas
nas
Iartist Lite
iartist_lite
Myqnapcloud
myqnapcloud
Qss
qss
Qusbcam2
qusbcam2
Qmailagent
qmailagent
Kazoo Server
kazoo_server
Ts 469u
ts-469u
Ts Ec1679u Rp
ts-ec1679u-rp
Ts 459u
ts-459u
Ss 839
ss-839
Sinage Station
sinage_station
Qts Helpdesk
qts_helpdesk
Qsync
qsync
Qfinder Pro
qfinder_pro
Roon Server
roon_server
Image2pdf
image2pdf
Ragic Cloud Db
ragic_cloud_db
Qfile
qfile
Qvr Pro Client
qvr_pro_client
Qvr Firmware
qvr_firmware
Ai Core
ai_core

CVEs (635)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qnap
1Music Station
Nov 21, 2024
Nov 2, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versio...Show more
If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.Show less
1Qnap
1Music Station
Nov 21, 2024
Nov 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions...Show more
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.Show less
1Qnap
1Music Station
Nov 21, 2024
Nov 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versio...Show more
If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.Show less
1Qnap
1Qts
Nov 3, 2025
Oct 28, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.120...Show more
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.Show less
1Qnap
1Qts
Nov 3, 2025
Oct 28, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201...Show more
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.Show less
1Qnap
1Qts
Nov 3, 2025
Oct 28, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS...Show more
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and laterShow less
1Qnap
1Helpdesk
Nov 21, 2024
Sep 11, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could allow attackers to force NAS users to execute unintentional actions th...Show more
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could allow attackers to force NAS users to execute unintentional actions through a web application. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.Show less
1Qnap
1Helpdesk
Nov 21, 2024
Sep 11, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sensitive information. QNAP has already fixed the issue in Helpdesk 3.0.3...Show more
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sensitive information. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.Show less
1Qnap
1Helpdesk
Nov 21, 2024
Sep 11, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could allow an attacker to spoof a trusted entity by interfering in the commun...Show more
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.Show less
1Qnap
1Helpdesk
Jun 17, 2026
Jul 1, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive data on QNAP Kayako server with API keys. We have replaced the API key to...Show more
This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive data on QNAP Kayako server with API keys. We have replaced the API key to mitigate the vulnerability, and already fixed the issue in Helpdesk 3.0.1 and later versions.Show less
1Qnap
1Viocard 300 Firmware
Nov 21, 2024
Feb 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
QNAP VioCard 300 has hardcoded RSA private keys.
1Qnap
1Photo Station
Jun 17, 2026
Dec 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
1Qnap
1Photo Station
Jun 17, 2026
Dec 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
1Qnap
1Qts
Jun 17, 2026
Dec 5, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
1Qnap
1Photo Station
Jun 17, 2026
Dec 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.
1Qnap
1Music Station
Jun 17, 2026
Dec 5, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
This cross-site scripting (XSS) vulnerability in Music Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Music Sta...Show more
This cross-site scripting (XSS) vulnerability in Music Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Music Station to their latest versions.Show less
1Qnap
1Video Station
Jun 17, 2026
Dec 5, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
This cross-site scripting (XSS) vulnerability in Video Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Video Sta...Show more
This cross-site scripting (XSS) vulnerability in Video Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Video Station to their latest versions.Show less
1Qnap
1Qts
Jun 17, 2026
Dec 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This improper link resolution vulnerability allows remote attackers to access system files. To fix this vulnerability, QNAP recommend updating QTS to their latest versions.
1Qnap
1Netbak Replicator
Jun 17, 2026
Dec 4, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An unquoted service path vulnerability is reported to affect the service QVssService in QNAP NetBak Replicator. This vulnerability could allow an authorized but non-privileged local user to execute arbitrary code with el...Show more
An unquoted service path vulnerability is reported to affect the service QVssService in QNAP NetBak Replicator. This vulnerability could allow an authorized but non-privileged local user to execute arbitrary code with elevated system privileges. QNAP have already fixed this issue in QNAP NetBak Replicator 4.5.12.1108.Show less
1Qnap
1Qts
Jun 17, 2026
Dec 4, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS. If exploited, this vulnerability may allow an attacker to inject and execute scripts on the administrator console. T...Show more
A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS. If exploited, this vulnerability may allow an attacker to inject and execute scripts on the administrator console. To fix this vulnerability, QNAP recommend updating QTS to the latest version.Show less