Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

QNAP Systems Inc. — Vulnerabilities & Security Advisories 532

Browse all 532 CVE security advisories affecting QNAP Systems Inc.. AI-powered Chinese analysis, POCs, and references for each vulnerability.

QNAP Systems Inc. manufactures network-attached storage devices and enterprise storage solutions, primarily serving small to medium-sized businesses and home users seeking centralized data management. Historically, the company’s firmware has exhibited a high volume of vulnerabilities, including remote code execution, cross-site scripting, and privilege escalation flaws. These issues often stem from insufficient input validation and improper access controls within the web management interface or embedded services. Notable incidents involve critical RCE vulnerabilities that allow unauthenticated attackers to gain full system control, exposing connected data to theft or ransomware encryption. The sheer number of recorded CVEs highlights persistent challenges in secure coding practices and rigorous patch management across its diverse product line. While QNAP provides security updates, the frequency of disclosed flaws necessitates strict network segmentation and proactive monitoring for administrators relying on these storage appliances for critical infrastructure.

Found 220 results / 532Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2023-32972 QTS, QuTS hero, QuTScloud — QTSCWE-120 3.8 Low2023-10-06
CVE-2023-32971 QTS, QuTS hero, QuTScloud — QTSCWE-120 3.8 Low2023-10-06
CVE-2023-23363 QTS — QTSCWE-120 8.1 High2023-09-22
CVE-2023-23362 QTS, QuTS hero, QuTScloud — QTSCWE-78 8.8 High2023-09-22
CVE-2023-34973 QTS, QuTS hero — QTSCWE-331 3.1 Low2023-08-24
CVE-2023-34972 QTS, QuTS hero and QuTScloud — QTSCWE-319 3.5 Low2023-08-24
CVE-2023-34971 QTS, QuTS hero — QTSCWE-326 7.1 High2023-08-24
CVE-2023-23355 QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances), QVR — QTSCWE-77 6.6 Medium2023-03-29
CVE-2022-27597 QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances) — QTSCWE-1295 2.7 Low2023-03-29
CVE-2022-27598 QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances) — QTSCWE-125 2.7 Low2023-03-29
CVE-2021-44053 Reflected XSS — QTSCWE-79 5.7 Medium2022-05-05
CVE-2021-34343 Buffer Overflow Vulnerability in QTS, QuTS hero, and QuTScloud — QTSCWE-787 6.0 Medium2021-09-10
CVE-2021-28816 Stack Buffer Overflow Vulnerabilities in QTS, QuTS hero, and QuTScloud — QTSCWE-787 7.6 High2021-09-10
CVE-2018-19957 Insufficient HTTP Security Headers in QTS, QuTS hero, and QuTScloud — QTSCWE-1021 6.1 -2021-09-10
CVE-2021-28804 Command Injection Vulnerabilities in QTS and QuTS hero — QTSCWE-78 9.8 -2021-07-01
CVE-2021-28802 Command Injection Vulnerabilities in QTS and QuTS hero — QTSCWE-78 9.8 -2021-07-01
CVE-2020-36194 XSS Vulnerability in QTS and QuTS heroCommand Injection Vulnerabilities in QTS and QuTS hero — QTSCWE-79 6.1 Medium2021-07-01
CVE-2021-28800 Command Injection Vulnerability in QTS — QTSCWE-78 8.1 High2021-06-24
CVE-2021-28806 DOM-Based XSS Vulnerability in QTS and QuTS hero — QTSCWE-79 5.7 Medium2021-06-03
CVE-2021-28798 Relative Path Traversal Vulnerability in QTS and QuTS hero — QTSCWE-284 8.8 High2021-05-21
CVE-2020-2509 Command Injection Vulnerability in QTS and QuTS hero — QTSCWE-77 9.8 -2021-04-17
CVE-2020-36195 SQL Injection Vulnerability in Multimedia Console and the Media Streaming Add-On — QTSCWE-20 9.8 Critical2021-04-17
CVE-2018-19942 Cross-site Scripting Vulnerability in File Station — QTSCWE-79 6.1 -2021-04-16
CVE-2020-2508 Command Injection Vulnerability in QTS and QuTS hero — QTSCWE-77 7.2 High2021-01-11
CVE-2018-19941 Cleartext Storage of Sensitive Information in Cookies — QTSCWE-315 7.5 -2020-12-31
CVE-2018-19944 Cleartext Transmission of Sensitive Information in SNMP — QTSCWE-311 7.5 -2020-12-31
CVE-2018-19945 Improper Limitation of a Pathname to a Restricted Directory in QTS — QTSCWE-20 7.5 -2020-12-31
CVE-2020-25847 Command Injection Vulnerability in QTS and QuTS hero — QTSCWE-77 8.8 High2020-12-29
CVE-2020-2498 Cross-site scripting vulnerability in QTS and QuTS hero — QTSCWE-79 6.1 -2020-12-10
CVE-2020-2497 Cross-site scripting vulnerability in QTS and QuTS hero — QTSCWE-79 6.1 -2020-12-10

This page lists every published CVE security advisory associated with QNAP Systems Inc.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.