Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Unraid

First CVE: Mar 16, 2020Active for: 6 yearsTotal CVEs: 7

Unraid is a specialized operating system for personal and small-business network-attached storage and compute servers, with its vulnerability profile concentrated in the core Unraid system product. The durable signal centers on access-control and path-handling issues, including path traversal and comparison logic flaws, which reflect the product's need to manage file permissions and directory isolation in a multi-user storage context. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
8.7
Avg CVSS Score
Higher Avg CVSS Score than 83% of tracked vendors
28.6%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Unraid over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 16, 2020
6 years ago
Most Recent CVE
Jun 24, 2026
30 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-5847CRITICAL
Unraid through 6.8.0 allows Remote Code Execution.
Mar 16, 20209.898YESYES
CVE-2020-5849HIGH
Unraid 6.8.0 allows authentication bypass.
Mar 16, 20207.597YESYES
CVE-2026-9772HIGH
Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations o
Jun 24, 20268.838NONO
CVE-2026-9773HIGH
Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations
Jun 24, 20268.836NONO
CVE-2026-3838HIGH
Unraid Update Request Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid.
Mar 13, 20268.831NONO
CVE-2025-29266CRITICAL
Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication if a container is running in Host networking mode with Use
Mar 31, 20259.627NONO
CVE-2026-3839HIGH
Unraid Authentication Request Path Traversal Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of U
Mar 16, 20267.322NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
71%
29%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network6 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (14.3%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (42.9%)
High0 (0.0%)
None4 (57.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
2 CVEs
28.6% of CVEs· 100th percentile
Metasploit
2 CVEs
28.6% of CVEs· 99th percentile
Nuclei
1 CVE
14.3% of CVEs· 97th percentile
ExploitDB
2 CVEs
28.6% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Unraid.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Unraid — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Unraid's Products

View all 2 CNAs →

Top CWEs