qnap
613 tracked vulnerabilities.
CVE-2025-29885
HIGH
File Station 5 <5.5.6.4791 - Improper Certificate Validation
Jun 06, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-29884
HIGH
File Station 5 <5.5.6.4791 - Info Disclosure
Jun 06, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-29883
HIGH
File Station 5 <5.5.6.4791 - Improper Certificate Validation
Jun 06, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-29877
HIGH
QNAP File Station 5.5.6.4691-5.5.6.4846 - Authenticated Denial of Service via NULL Pointer Dereference
Jun 06, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-29876
HIGH
QNAP File Station 5.5.6.4691-5.5.6.4846 - Authenticated Denial of Service via NULL Pointer Dereference
Jun 06, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-29873
HIGH
QNAP File Station 5.5.6.4691-5.5.6.4846 - Authenticated Denial of Service via NULL Pointer Dereference
Jun 06, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-29872
HIGH
QNAP File Station 5.5.6.4691-5.5.6.4846 - Authenticated Denial of Service
Jun 06, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-29871
MEDIUM
File Station 5 <5.5.6.4847 - Info Disclosure
Jun 06, 2025
CVSS 5.5
EPSS 0.00
CVE-2025-22490
HIGH
QNAP File Station 5.5.6.4691-5.5.6.4846 - Authenticated Denial of Service via NULL Pointer Dereference
Jun 06, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-22486
HIGH
QNAP File Station 5.5.6.4691-5.5.6.4791 - Improper Certificate Validation
Jun 06, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-22482
HIGH
Qsync Central 4.5.0.3-4.5.0.5 - Authenticated Use of Externally-Controlled Format String
Jun 06, 2025
CVSS 8.1
EPSS 0.00
CVE-2025-22481
HIGH
QNAP QTS and QuTS hero - Authenticated OS Command Injection
Jun 06, 2025
CVSS 8.8
EPSS 0.01
CVE-2024-14026
HIGH
QNAP QTS/QuTS hero - Command Injection
Mar 11, 2026
CVSS 7.8
EPSS 0.00
CVE-2024-14025
MEDIUM
Video Station <5.8.2 - SQL Injection
Mar 11, 2026
CVSS 6.7
EPSS 0.00
CVE-2024-14024
MEDIUM
QNAP Video Station 5.0.0-5.8.1 - Improper Certificate Validation
Mar 11, 2026
CVSS 6.7
EPSS 0.00
CVE-2024-56808
HIGH
Media Streaming add-on <500.1.1.6 - Command Injection
Feb 11, 2026
CVSS 7.8
EPSS 0.00
CVE-2024-56807
MEDIUM
Media Streaming add-on <500.1.1.6 - Info Disclosure
Feb 11, 2026
CVSS 5.5
EPSS 0.00
CVE-2024-56804
HIGH
Video Station <5.8.4 - SQL Injection
Oct 03, 2025
CVSS 8.8
EPSS 0.00
CVE-2024-12923
MEDIUM
QNAP Photo Station 6.4.0-6.4.4 - Authenticated Stored Cross-Site Scripting
Aug 29, 2025
CVSS 5.4
EPSS 0.00
CVE-2024-56805
MEDIUM
QNAP QTS and QuTS hero - Heap-based Buffer Overflow
Jun 06, 2025
CVSS 5.4
EPSS 0.00
CVE-2024-50406
MEDIUM
QNAP License Center 1.9.36-1.9.48 - Cross-Site Scripting
Jun 06, 2025
CVSS 5.4
EPSS 0.00
CVE-2024-13088
HIGH
QHora - Auth Bypass
Jun 06, 2025
CVSS 7.8
EPSS 0.00
CVE-2024-13087
MEDIUM
QHora - Command Injection
Jun 06, 2025
CVSS 6.7
EPSS 0.00
CVE-2024-53700
HIGH
Qnap Qurouter - Command Injection
Mar 07, 2025
CVSS 7.2
EPSS 0.00
CVE-2024-53699
HIGH
QNAP QTS and QuTS hero - Out-of-bounds Write
Mar 07, 2025
CVSS 7.2
EPSS 0.00
Products
qts 272
quts_hero 223
qsync_central 62
qutscloud 62
file_station 48
photo_station 26
video_station 15
media_streaming_add-on 13
music_station 13
qurouter 12
helpdesk 11
qumagie 10
qvr 10
qulog_center 8
nas_proxy_server 7
q\'center 7
hybrid_backup_sync 6
notes_station_3 6
qvr_pro 6
license_center 5
multimedia_console 5
qunetswitch 5
qvr_elite 5
qvr_guard 5
qes 4
download_station 3
qcalagent 3
qufirewall 3
qvp-21a_firmware 3
qvp-41a_firmware 3
Quick Filters