QNAP Systems QTS

6 known vulnerabilities in QNAP Systems QTS, 2 critical, 4 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2020-2509 CVSS 9.8 critical · actively exploited QNAP Network-Attached Storage (NAS) Command Injection Vulnerability
  • CVE-2018-19953 CVSS 6.1 medium · actively exploited QNAP NAS File Station Cross-Site Scripting Vulnerability
  • CVE-2018-19949 CVSS 9.8 critical · actively exploited QNAP NAS File Station Command Injection Vulnerability
  • CVE-2018-19943 CVSS 5.4 medium · actively exploited QNAP NAS File Station Cross-Site Scripting Vulnerability

Latest vulnerabilities

  • CVE-2024-38639 CVSS 4.8 medium An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulnerability to…
  • CVE-2023-47218 CVSS 8.3 high An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability…
  • CVE-2020-2509 CVSS 9.8 critical · actively exploited QNAP Network-Attached Storage (NAS) Command Injection Vulnerability
  • CVE-2018-19953 CVSS 6.1 medium · actively exploited QNAP NAS File Station Cross-Site Scripting Vulnerability
  • CVE-2018-19949 CVSS 9.8 critical · actively exploited QNAP NAS File Station Command Injection Vulnerability
  • CVE-2018-19943 CVSS 5.4 medium · actively exploited QNAP NAS File Station Cross-Site Scripting Vulnerability