Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Qnap

160 known vulnerabilities

13
CRITICAL
32
HIGH
74
MEDIUM
1
LOW

Top Products

quts hero 43 qts 41 qsync central 28 file station 19 qumagie 4 qunetswitch 4 qurouter 4 license center 3 media streaming add-on 3 hyper data protector 2
120 CVEs · Page 2/3
6.5
CVE-2025-58470

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the

6.5
CVE-2025-58467

A relative path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user acc

4.9
CVE-2025-58466

A use of uninitialized variable vulnerability has been reported to affect several QNAP operating system versions. If a r

7.5
CVE-2025-57713

A weak authentication vulnerability has been reported to affect File Station 5. The remote attackers can then exploit th

4.9
CVE-2025-57711

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re

4.9
CVE-2025-57710

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re

8.1
CVE-2025-57709

A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th

6.5
CVE-2025-57708

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re

8.8
CVE-2025-57707

An improper neutralization of directives in statically saved code ('Static Code Injection') vulnerability has been repor

6.5
CVE-2025-54170

An out-of-bounds read vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account

6.5
CVE-2025-54169

An out-of-bounds read vulnerability has been reported to affect File Station 5. If a remote attacker gains a user accoun

4.9
CVE-2025-54163

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains an admin

4.9
CVE-2025-54162

A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator a

4.9
CVE-2025-54161

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r

4.9
CVE-2025-54155

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r

6.5
CVE-2025-54152

A use of out-of-range pointer offset vulnerability has been reported to affect Qsync Central. If a remote attacker gains

5.5
CVE-2025-54151

An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains

5.5
CVE-2025-54150

An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains

5.5
CVE-2025-54149

An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains

6.5
CVE-2025-54148

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac

6.5
CVE-2025-54147

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac

6.5
CVE-2025-54146

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac

6.5
CVE-2025-53598

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac

8.1
CVE-2025-52870

A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th

8.1
CVE-2025-52869

A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th

8.1
CVE-2025-52868

A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th

8.1
CVE-2025-48725

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker

8.1
CVE-2025-48724

A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th

8.1
CVE-2025-48723

A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th

6.5
CVE-2025-48722

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac

6.5
CVE-2025-47209

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac

4.9
CVE-2025-47205

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

8.8
CVE-2025-30276

An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user accoun

8.1
CVE-2025-30269

A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If a remote attack

6.5
CVE-2025-30266

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac

7.8
CVE-2024-56808

A command injection vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network

5.5
CVE-2024-56807

An out-of-bounds read vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local netwo

7.5
CVE-2025-9110

An exposure of sensitive system information to an unauthorized control sphere vulnerability has been reported to affect

6.5
CVE-2025-62852

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker

7.8
CVE-2025-62842

An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attac

3.3
CVE-2025-62840

A generation of error message containing sensitive information vulnerability has been reported to affect HBS 3 Hybrid Ba

9.8
CVE-2025-59389

An SQL injection vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit t

7.5
CVE-2025-59384

A path traversal vulnerability has been reported to affect Qfiling. The remote attackers can then exploit the vulnerabil

4.9
CVE-2025-59381

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker

4.9
CVE-2025-59380

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker

6.5
CVE-2025-53597

A buffer overflow vulnerability has been reported to affect License Center. If a remote attacker gains an administrator

6.5
CVE-2025-52871

An out-of-bounds read vulnerability has been reported to affect License Center. If a remote attacker gains a user accoun

6.5
CVE-2025-48721

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker

9.8
CVE-2025-11837

An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attacker

6.1
CVE-2025-62857

A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. The remote attackers can then exploit th

Frequently Asked Questions

How many CVEs affect Qnap?

Qnap has 160 CVE records in our database, including 14 critical and 45 high severity vulnerabilities.

What are the most severe Qnap vulnerabilities?

Qnap has 14 critical severity (CVSS 9.0+) and 45 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Qnap vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Qnap products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Qnap Vulnerabilities

CyberStrike scans your infrastructure for Qnap vulnerabilities and provides real-time remediation guidance.

Get Started