QNAP Systems, Inc.

First CVE: Sep 14, 2017Active for: 9 years
612
CVEs Published
More CVEs Published than 88% of tracked CNAs
61.2
Avg CVEs / Year
More Avg CVEs / Year than 85% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked CNAs
2.0%
In CISA KEV
Higher KEV Rate than 91% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by QNAP Systems, Inc. as a CNA, 98.5% affect products that QNAP Systems, Inc. develops as a vendor.

98.5%
Self-reported: 603Third-party: 9

Of all the CVEs published that affect products developed by QNAP Systems, Inc., 95.0% are self-published by QNAP Systems, Inc. as a CNA.

95.0%
Self-published: 603Published by other CNAs: 32

Trends Over Time

The number and severity of CVEs published by QNAP Systems, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 14, 2017
8 years ago
Most Recent CVE
Jun 10, 2026
43 days ago

Top CVEs

All CVEs published by QNAP Systems, Inc. as a CNA, regardless of affected vendor or product.

612 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station t
Dec 5, 20199.898YESYES
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to
Dec 5, 20199.898YESYES
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station t
Dec 5, 20199.897YESYES
An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify syst
Sep 8, 20229.196YESYES
An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in
May 13, 20219.896YESYES
An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated us
Dec 8, 20238.892YESNO
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via
Feb 13, 20248.388NOYES
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised ap
Apr 17, 20219.883YESNO
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2
Oct 28, 20209.879YESNO
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest v
Dec 5, 20199.876YESNO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA612 CVEs
Severity distribution among all CVEs352,101 CVEs
LowMediumHighCritical
Attack Vector
Local41 (6.7%)
Network562 (91.8%)
Unknown0 (0.0%)
Physical2 (0.3%)
Adjacent Network7 (1.1%)
Attack Complexity
Low606 (99.0%)
High6 (1.0%)
Unknown0 (0.0%)
User Interaction
None520 (85.0%)
Unknown0 (0.0%)
Required88 (14.4%)
Privileges Required
Low217 (35.5%)
High186 (30.4%)
None209 (34.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (612 CVEs).

CISA KEV
12 CVEs
2.0% of CVEs· 91st percentile
Metasploit
7 CVEs
1.1% of CVEs· 87th percentile
Nuclei
7 CVEs
1.1% of CVEs· 81st percentile
ExploitDB
8 CVEs
1.3% of CVEs· 84th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by QNAP Systems, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by QNAP Systems, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs