Helpdesk
Vendor:
First CVE: Aug 13, 2018 · Active for 7 years
11
Total CVEs
More Total CVEs than 89% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
9.1%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Helpdesk over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 13, 2018
7 years ago
Most Recent CVE
Mar 7, 2025
507 days ago
CVE Severity & Scoring
Helpdesk11 CVEs
45%
27%
27%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None8 (72.7%)
Unknown0 (0.0%)
Required3 (27.3%)
Privileges Required
Low2 (18.2%)
High1 (9.1%)
None8 (72.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-2506CRITICAL The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of | Feb 3, 2021 | 9.8 | 68 | YES | NO |
CVE-2020-2507CRITICAL The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. T | Feb 3, 2021 | 9.8 | 31 | NO | NO |
CVE-2018-0714CRITICAL Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 20180528 and their earlier versi | Aug 13, 2018 | 9.8 | 31 | NO | NO |
CVE-2021-28814HIGH An improper access control vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows remote attackers to compromise the security of the software. | Jun 11, 2021 | 8.8 | 27 | NO | NO |
CVE-2024-50394HIGH An improper certificate validation vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow remote attackers to compromise the security of th | Mar 7, 2025 | 8.8 | 26 | NO | NO |
CVE-2018-0728HIGH This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerability, QNAP recommend updating QTS and Helpdesk to their lates | Dec 4, 2019 | 7.5 | 23 | NO | NO |
CVE-2018-19948MEDIUM The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could allow attackers to force NAS u | Sep 11, 2020 | 6.5 | 22 | NO | NO |
CVE-2018-19947MEDIUM The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sensitive information. QNAP has al | Sep 11, 2020 | 6.5 | 22 | NO | NO |
CVE-2018-19946MEDIUM The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could allow an attacker to spoof a tru | Sep 11, 2020 | 5.9 | 20 | NO | NO |
CVE-2020-2500MEDIUM This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive data on QNAP Kayako server with AP | Jul 1, 2020 | 6.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
1 CVE
9.1% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Helpdesk
Top CWEs
Versions
No cataloged versions.