← Back

Qnap

qnap

635 CVEs • 143 products

Products (143)

Click to collapse
Toggle
Qts
qts
Quts Hero
quts_hero
Qutscloud
qutscloud
Qsync Central
qsync_central
File Station
file_station
Photo Station
photo_station
Video Station
video_station
Music Station
music_station
Qumagie
qumagie
Qurouter
qurouter
Helpdesk
helpdesk
Qvr
qvr
Qulog Center
qulog_center
Q'center
q'center
Qvr Pro
qvr_pro
Qunetswitch
qunetswitch
Qvr Elite
qvr_elite
Qvr Guard
qvr_guard
Qes
qes
Qcalagent
qcalagent
Qvpn
qvpn
Qufirewall
qufirewall
Nas
nas
Iartist Lite
iartist_lite
Myqnapcloud
myqnapcloud
Qss
qss
Qusbcam2
qusbcam2
Qmailagent
qmailagent
Kazoo Server
kazoo_server
Ts 469u
ts-469u
Ts Ec1679u Rp
ts-ec1679u-rp
Ts 459u
ts-459u
Ss 839
ss-839
Sinage Station
sinage_station
Qts Helpdesk
qts_helpdesk
Qsync
qsync
Qfinder Pro
qfinder_pro
Roon Server
roon_server
Image2pdf
image2pdf
Ragic Cloud Db
ragic_cloud_db
Qfile
qfile
Qvr Pro Client
qvr_pro_client
Qvr Firmware
qvr_firmware
Ai Core
ai_core

CVEs (635)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qnap
1Qts
May 13, 2026
Dec 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary c...Show more
A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.Show less
1Qnap
1Qts
May 13, 2026
Dec 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code...Show more
A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.Show less
1Qnap
1Qts
May 13, 2026
Dec 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code...Show more
A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.Show less
1Qnap
1Qts
May 13, 2026
Dec 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbi...Show more
A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.Show less
1Qnap
1Qts
May 13, 2026
Dec 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on...Show more
A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.Show less
1Qnap
1Qsync
May 13, 2026
Dec 11, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A DLL Hijacking vulnerability in QNAP Qsync for Windows (exe) version 4.2.2.0724 and earlier could allow remote attackers to execute arbitrary code on Windows machines.
1Qnap
1Video Station
May 13, 2026
Nov 22, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on the QNAP Video Station 5.1.3 (for QTS 4.3.3), 5.2.0 (for QTS 4.3.4), and earlier.
1Qnap
1Music Station
May 13, 2026
Oct 6, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
QNAP discovered a number of command injection vulnerabilities found in Music Station versions 4.8.6 (for QTS 4.2.x), 5.0.7 (for QTS 4.3.x), and earlier. If exploited, these vulnerabilities may allow a remote attacker to...Show more
QNAP discovered a number of command injection vulnerabilities found in Music Station versions 4.8.6 (for QTS 4.2.x), 5.0.7 (for QTS 4.3.x), and earlier. If exploited, these vulnerabilities may allow a remote attacker to run arbitrary commands on the NAS.Show less
1Qnap
1Qts Helpdesk
May 13, 2026
Oct 6, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection on the application and obtain Helpdesk application information. A remote attacker does not require a...Show more
QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection on the application and obtain Helpdesk application information. A remote attacker does not require any privileges to successfully execute this attack.Show less
1Qnap
1Qts
May 13, 2026
Sep 19, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system commands as the root user of the NAS application.
1Qnap
1Qts
May 13, 2026
Sep 14, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 and QTS 4.3.3.0299 build 20170901. This particular vulnerability allows a remote at...Show more
QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 and QTS 4.3.3.0299 build 20170901. This particular vulnerability allows a remote attacker to execute commands on a QNAP NAS using a transcoding service on port 9251. A remote user does not require any privileges to successfully execute an attack.Show less
1Qnap
1Ts 212p Firmware
May 13, 2026
Aug 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Unprivileged user can access all functions in the Surveillance Station component in QNAP TS212P devices with firmware 4.2.1 build 20160601. Unprivileged user cannot login at front end but with that unprivileged user SID,...Show more
Unprivileged user can access all functions in the Surveillance Station component in QNAP TS212P devices with firmware 4.2.1 build 20160601. Unprivileged user cannot login at front end but with that unprivileged user SID, all function can access at Surveillance Station.Show less
1Qnap
1Qts
May 13, 2026
Jun 15, 2017
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the issue in QTS 4.2.6 build 20170517, QTS 4.3.3.0174 build 20170503 and late...Show more
This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the issue in QTS 4.2.6 build 20170517, QTS 4.3.3.0174 build 20170503 and later versions.Show less
1Qnap
1Qts
May 13, 2026
Jun 15, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
QNAP QTS before 4.2.6 build 20170517 has a flaw in the change password function.
1Qnap
1Qts
May 13, 2026
Mar 23, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.
1Qnap
1Qts
May 13, 2026
Mar 23, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.
1Qnap
1Qts
May 13, 2026
Mar 23, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors.
1Qnap
1Qts
May 13, 2026
Mar 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by reading data in an XOR format within the /etc/config/uLinux.conf configuration file.
1Qnap
1Qts
May 6, 2026
Jul 3, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in File Station in QNAP QTS before 4.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Qnap
2Iartist Lite
Signage Station
May 6, 2026
Feb 27, 2016
N/A· v4
7.5 HIGH· v3
8.5 HIGH· v2
QNAP iArtist Lite before 1.4.54, as distributed with QNAP Signage Station before 2.0.1, allows remote authenticated users to gain privileges by registering an executable file, and then waiting for this file to be run in...Show more
QNAP iArtist Lite before 1.4.54, as distributed with QNAP Signage Station before 2.0.1, allows remote authenticated users to gain privileges by registering an executable file, and then waiting for this file to be run in a privileged context after a reboot.Show less