qnap has 5 CVEs on record between 2020 and 2026. The median CVSS is 8.0 (high), with 1 rated critical. 60% have been exploited in the wild — well above the 1% corpus average, so qnap flaws are worth patching on sight. The median gap from publication to a KEV listing is 573 days (3 cases). Most affected products: qts (3), hybrid_backup_sync (1), notification_center (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 60% vs 1% corpus
- Median CVSS
- 8.0
- Publish → KEV
- 573 d median(3)
- Last 90 days
- 0 prev 1
Products
- qts 3
- hybrid_backup_sync 1
- notification_center 1
Worst active — by depth score
CVE-2018-19949Critical· 9.8If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands89CVE-2018-19943High· 8.0If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code78CVE-2018-19953Medium· 6.1If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code68CVE-2025-58468High· 8.8A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center48CVE-2025-62842High· 7.8An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync43
qnap vulnerabilities
CVEs affecting qnap, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2025-58468High· 8.8A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center
A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerabi…
CVE-2025-62842High· 7.8An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync
An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read or modify files or directories. We h…
CVE-2018-19953Medium· 6.1CISA KEV0dayIf exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 202001…
CVE-2018-19949Critical· 9.8CISA KEV0dayIf exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130…
CVE-2018-19943High· 8.0CISA KEV0dayIf exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build …