QNAP Systems Inc. vendor intelligence

QNAP Systems Inc. Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting QNAP Systems Inc. products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Total KEVs
14
Known exploited vulnerabilities affecting QNAP Systems Inc. products
In CISA KEV
8
Records also listed in the official catalog
Beyond CISA KEV
6
Additional exploited CVEs absent from CISA KEV
Sensor Observed
0
QNAP Systems Inc. KEVs with sensor-observed exploitation activity

The catalog gap matters for QNAP Systems Inc. exposure

Six of the fourteen exploited QNAP Systems Inc. CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 43% of this vendor portfolio.

57%
Covered by CISA
43%
Beyond CISA
8
Product families

Attested QNAP Systems Inc. CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2023-50358

QTS, QuTS hero, QuTScloud

QTS, QuTS hero, QuTScloud High Beyond CISA 26 Oct 2025
CVE-2023-45038

Music Station

Music Station High Beyond CISA 21 Aug 2025
CVE-2020-2507

command injection vulnerability in Helpdesk

Helpdesk High Beyond CISA 16 Aug 2025
CVE-2023-47218

QTS, QuTS hero, QuTScloud

QTS, QuTS hero, QuTScloud High Beyond CISA 05 Jun 2025
CVE-2024-21899

QTS, QuTS hero, QuTScloud

QTS, QuTS hero, QuTScloud High Beyond CISA 27 Apr 2025
CVE-2020-2506

improper access control vulnerability in Helpdesk

Helpdesk Confirmed In CISA 25 Mar 2022
CVE-2021-28799

Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)

HBS 3, HBS 2, HBS 1.3 Confirmed In CISA 31 Mar 2022
CVE-2020-2509

Command Injection Vulnerability in QTS and QuTS hero

QTS, QuTS hero Confirmed In CISA 11 Apr 2022
CVE-2018-19943

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in...

QTS Confirmed In CISA 24 May 2022
CVE-2018-19949

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the...

QTS Confirmed In CISA 24 May 2022
CVE-2018-19953

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in...

QTS Confirmed In CISA 24 May 2022
CVE-2022-27593

DeadBolt Ransomware

Photo Station Confirmed In CISA 08 Sep 2022
CVE-2023-47565

Legacy VioStor NVR

VioStor NVR Confirmed In CISA 21 Dec 2023
CVE-2024-27130

QTS, QuTS hero

QTS, QuTS hero High Beyond CISA 21 May 2024

Showing 14 of 14 QNAP Systems Inc. known exploited vulnerabilities.

Recurring weakness patterns

Neutralization, neutralization, and neutralization account for twelve mapped occurrences across this QNAP Systems Inc. KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.