VulnSea

qnap has 5 CVEs on record between 2020 and 2026. The median CVSS is 8.0 (high), with 1 rated critical. 60% have been exploited in the wild — well above the 1% corpus average, so qnap flaws are worth patching on sight. The median gap from publication to a KEV listing is 573 days (3 cases). Most affected products: qts (3), hybrid_backup_sync (1), notification_center (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
60% vs 1% corpus
Median CVSS
8.0
Publish → KEV
573 d median(3)
Last 90 days
0 prev 1

Products

  • qts 3
  • hybrid_backup_sync 1
  • notification_center 1
5
Total CVEs
1
Critical
3
CISA KEV
3
Exploited

qnap vulnerabilities

CVEs affecting qnap, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2025-58468High· 8.8
3mo ago

A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center

A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerabi…

Twilightqnap · notification_centerEPSS 0.16%via NVD
CVE-2025-62842High· 7.8
8mo ago

An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync

An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read or modify files or directories. We h…

Twilightqnap · hybrid_backup_syncEPSS 0.26%via NVD
CVE-2018-19953Medium· 6.1CISA KEV0day
5y ago

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 202001…

Midnightqnap · qtsEPSS 24%via NVD
CVE-2018-19949Critical· 9.8CISA KEV0day
5y ago

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130…

Hadalqnap · qtsEPSS 24%via NVD
CVE-2018-19943High· 8.0CISA KEV0day
5y ago

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build …

Abyssalqnap · qtsEPSS 18%via NVD
qnap vulnerabilities (CVEs) · VulnSea