Skip to main content

Vendor/product archive

qnap / qts CVEs

Beta · best-effort

320 CVEs tagged to qnap / qts50 Critical, 62 High, 151 Medium, 57 Low, 0 Unrated.

CVE-2026-24719

Published Jun 10, 2026

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit th…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24717

Published Jun 10, 2026

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the v…

CVSS 1.2 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24716

Published Jun 10, 2026

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exp…

CVSS 1.2 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22893

Published Jun 10, 2026

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit th…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-66281

Published Jun 10, 2026

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch a de…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-66280

Published Jun 10, 2026

An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can t…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-66279

Published Jun 10, 2026

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit th…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-66273

Published Jun 10, 2026

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit th…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-66276

Published Jun 10, 2026

QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-62858

Published Jun 9, 2026

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41539

Published Jun 9, 2026

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass se…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-14026

Published Mar 11, 2026

A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who have also gained a user account…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-66277

Published Feb 11, 2026

A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to traverse the file sys…

CVSS 9.2 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-58466

Published Feb 11, 2026

A use of uninitialized variable vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can the…

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-48725

Published Feb 11, 2026

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerabil…

CVSS 0.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-47205

Published Feb 11, 2026

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exp…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-9110

Published Jan 2, 2026

An exposure of sensitive system information to an unauthorized control sphere vulnerability has been reported to affect several QNAP operating system versions. The remote attacker…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-62852

Published Jan 2, 2026

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the…

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-59381

Published Jan 2, 2026

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the v…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59380

Published Jan 2, 2026

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the v…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48721

Published Jan 2, 2026

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the…

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-57705

Published Jan 2, 2026

An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrat…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54166

Published Jan 2, 2026

An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54165

Published Jan 2, 2026

An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54164

Published Jan 2, 2026

An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 320 CVEsPage 1 of 13