Qts
Vendor:
First CVE: Jan 9, 2014 · Active for 12 years
283
Total CVEs
More Total CVEs than 100% of tracked products
21.8
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 45% of tracked products
2.5%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Qts over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 9, 2014
12 years ago
Most Recent CVE
Jun 10, 2026
48 days ago
CVE Severity & Scoring
Qts283 CVEs
42%
41%
15%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local5 (1.8%)
Network271 (95.8%)
Unknown2 (0.7%)
Physical0 (0.0%)
Adjacent Network5 (1.8%)
Attack Complexity
Low277 (97.9%)
High4 (1.4%)
Unknown2 (0.7%)
User Interaction
None252 (89.0%)
Unknown2 (0.7%)
Required29 (10.2%)
Privileges Required
Low56 (19.8%)
High133 (47.0%)
None92 (32.5%)
Unknown2 (0.7%)
Top CVEs
Signals from CVEs in this product scope (283 CVEs).
283 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-6271CRITICAL GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra | Sep 24, 2014 | 9.8 | 99 | YES | YES |
CVE-2014-7169CRITICAL GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri | Sep 25, 2014 | 9.8 | 98 | YES | YES |
CVE-2023-47218HIGH An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via | Feb 13, 2024 | 8.3 | 88 | NO | YES |
CVE-2020-2509CRITICAL A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised ap | Apr 17, 2021 | 9.8 | 83 | YES | NO |
CVE-2018-19949CRITICAL If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2 | Oct 28, 2020 | 9.8 | 79 | YES | NO |
CVE-2017-6360CRITICAL QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors. | Mar 23, 2017 | 9.8 | 78 | NO | YES |
CVE-2019-7193CRITICAL This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest v | Dec 5, 2019 | 9.8 | 76 | YES | NO |
CVE-2017-6361CRITICAL QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors. | Mar 23, 2017 | 9.8 | 74 | NO | YES |
CVE-2018-19953MEDIUM If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4 | Oct 28, 2020 | 6.1 | 72 | YES | NO |
CVE-2018-19943MEDIUM If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS | Oct 28, 2020 | 5.4 | 66 | YES | NO |
Exploit Exposure
Signals from CVEs in this product scope (283 CVEs).
CISA KEV
7 CVEs
2.5% of CVEs· 98th percentile
Metasploit
3 CVEs
1.1% of CVEs· 97th percentile
Nuclei
2 CVEs
0.7% of CVEs· 96th percentile
ExploitDB
6 CVEs
2.1% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (283 CVEs).
Media Mentions
Signals from CVEs in this product scope (283 CVEs).
Top CNAs Publishing CVEs For Qts
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.2.9.3451 | 1 | 6.1 | 0.2% | 0 | 0 |
| 5.2.9.3410 | 1 | 6.1 | 0.2% | 0 | 0 |
| 5.2.8.3359 | 2 | 6.3 | 0.3% | 0 | 0 |
| 5.2.8.3350 | 2 | 6.3 | 0.3% | 0 | 0 |
| 5.2.8.3332 | 5 | 7.1 | 0.4% | 0 | 0 |
| 5.2.7.3297 | 11 | 6.4 | 0.4% | 0 | 0 |
| 5.2.7.3256 | 15 | 7.0 | 0.5% | 0 | 0 |
| 5.2.6.3229 | 35 | 6.3 | 0.4% | 0 | 0 |
| 5.2.6.3195 | 35 | 6.3 | 0.4% | 0 | 0 |
| 5.2.5.3145 | 61 | 5.8 | 0.4% | 0 | 0 |
| 5.2.4.3092 | 72 | 6.0 | 0.4% | 0 | 0 |
| 5.2.4.3079 | 72 | 6.0 | 0.4% | 0 | 0 |
| 5.2.4.3070 | 74 | 6.0 | 0.4% | 0 | 0 |
| 5.2.3.3006 | 74 | 6.0 | 0.4% | 0 | 0 |
| 5.2.2.2950 | 81 | 6.0 | 0.4% | 0 | 0 |
| 5.2.1.2930 | 89 | 6.2 | 0.4% | 0 | 0 |
| 5.2.0.2860 | 105 | 6.2 | 0.5% | 0 | 0 |
| 5.2.0.2851 | 105 | 6.2 | 0.5% | 0 | 0 |
| 5.2.0.2823 | 105 | 6.2 | 0.5% | 0 | 0 |
| 5.2.0.2802 | 105 | 6.2 | 0.5% | 0 | 0 |