QNAP vendor intelligence

QNAP Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting QNAP products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse QNAP KEVs Full KEV feed
Total KEVs
18
Known exploited vulnerabilities affecting QNAP products
In CISA KEV
12
Records also listed in the official catalog
Beyond CISA KEV
6
Additional exploited CVEs absent from CISA KEV
Sensor Observed
0
QNAP KEVs with sensor-observed exploitation activity

The catalog gap matters for QNAP exposure

Six of the eighteen exploited QNAP CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss one-third of this vendor portfolio.

67%
Covered by CISA
33%
Beyond CISA
10
Product families

Attested QNAP CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2023-50358

QTS, QuTS hero, QuTScloud

QTS, QuTS hero, QuTScloud High Beyond CISA 26 Oct 2025
CVE-2023-45038

Music Station

Music Station High Beyond CISA 21 Aug 2025
CVE-2020-2507

command injection vulnerability in Helpdesk

Helpdesk High Beyond CISA 16 Aug 2025
CVE-2023-47218

QTS, QuTS hero, QuTScloud

QTS, QuTS hero, QuTScloud High Beyond CISA 05 Jun 2025
CVE-2024-21899

QTS, QuTS hero, QuTScloud

QTS, QuTS hero, QuTScloud High Beyond CISA 27 Apr 2025
CVE-2020-2506

improper access control vulnerability in Helpdesk

Helpdesk Confirmed In CISA 25 Mar 2022
CVE-2021-28799

Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)

HBS 3, HBS 2, HBS 1.3 Confirmed In CISA 31 Mar 2022
CVE-2020-2509

Command Injection Vulnerability in QTS and QuTS hero

QTS, QuTS hero Confirmed In CISA 11 Apr 2022
CVE-2018-19943

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in...

QTS Confirmed In CISA 24 May 2022
CVE-2018-19949

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the...

QTS Confirmed In CISA 24 May 2022
CVE-2018-19953

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in...

QTS Confirmed In CISA 24 May 2022
CVE-2019-7192

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP...

QNAP NAS devices running Photo Station Confirmed In CISA 08 Jun 2022
CVE-2019-7193

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP...

QNAP NAS devices Confirmed In CISA 08 Jun 2022
CVE-2019-7194

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP...

QNAP NAS devices running Photo Station Confirmed In CISA 08 Jun 2022
CVE-2019-7195

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP...

QNAP NAS devices running Photo Station Confirmed In CISA 08 Jun 2022
CVE-2022-27593

DeadBolt Ransomware

Photo Station Confirmed In CISA 08 Sep 2022
CVE-2023-47565

Legacy VioStor NVR

VioStor NVR Confirmed In CISA 21 Dec 2023
CVE-2024-27130

QTS, QuTS hero

QTS, QuTS hero High Beyond CISA 21 May 2024

Showing 18 of 18 QNAP known exploited vulnerabilities.

Recurring weakness patterns

Neutralization, neutralization, and neutralization account for twelve mapped occurrences across this QNAP KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.