Vulnerabilities
617 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-26239 | A buffer overflow vulnerability has been reported to affect File Station 5. A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5208 and later NVD description · AI analysis pending | 6.3 group max | <1% |
| — | ||
| CVE-2026-26237 | A missing authorization vulnerability has been reported to affect QuMagie. A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the following version: QuMagie 2.9.0 and later NVD description · AI analysis pending | 6.6 | <1% |
| — | ||
| CVE-2025-66276 | QuTS hero is not affected. QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later NVD description · AI analysis pending | 9.2 group max | <1% |
| — | ||
| CVE-2025-62851 | A path traversal vulnerability has been reported to affect License Center. A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: License Center 1.9.56 and later NVD description · AI analysis pending | 4.6 | <1% |
| — | ||
| CVE-2025-62850 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3459 build 20260409 and later NVD description · AI analysis pending | 5.1 | <1% |
| — | ||
| CVE-2025-58468 | A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: Notification Center 1.10.0.3291 and later NVD description · AI analysis pending | 5.1 | <1% |
| — | ||
| CVE-2026-44083 +1 in the same advisory: …26236 | An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to gain unintended privileges. We have already fixed the vulnerability in the following version: QuMagie 2.9.1 and later NVD description · AI analysis pending | 8.7 group max | <1% |
| — | ||
| CVE-2026-41539 +1 in the same advisory: …62858 | A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.3499 build 20260514 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3500 build 20260520 and later NVD description · AI analysis pending | 6.3 group max | <1% |
| — | ||
| CVE-2026-22897 | A command injection vulnerability has been reported to affect QuNetSwitch. A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.4.0415 and later NVD description · AI analysis pending | 8.1 group max | 1% |
| — | ||
| CVE-2026-22898 | A missing authentication for critical function vulnerability has been reported to affect QVR Pro. A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerability to gain access to the system. We have already fixed the vulnerability in the following version: QVR Pro 2.7.4.14 and later NVD description · AI analysis pending | 9.3 | <1% |
| — | ||
| CVE-2026-22895 | A cross-site scripting (XSS) vulnerability has been reported to affect QuFTP Service. A cross-site scripting (XSS) vulnerability has been reported to affect QuFTP Service. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QuFTP Service 1.4.3 and later QuFTP Service 1.5.2 and later QuFTP Service 1.6.2 and later NVD description · AI analysis pending | 6.2 | <1% |
| — | ||
| CVE-2025-62846 | An SQL injection vulnerability has been reported to affect QHora. An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: QuRouter 2.6.2.007 and later NVD description · AI analysis pending | 7.3 group max | <1% |
| — | ||
| CVE-2025-59383 | A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Media Streaming Add-on 500.1.1 and later NVD description · AI analysis pending | 2.7 | <1% |
| — | ||
| CVE-2025-59388 | A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit the vulnerability to gain unauthorized access. We have already fixed the vulnerability in the following version: Hyper Data Protector 2.3.1.455 and later NVD description · AI analysis pending | 6.6 | <1% |
| — | ||
| CVE-2024-14026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.3.3006 build 20250108 and later QuTS hero h5.1.9.2954 build 20241120 and later QuTS hero h5.2.3.3006 build 20250108 and later NVD description · AI analysis pending | 2.0 | <1% |
| — | ||
| CVE-2024-14025 +1 in the same advisory: …14024 | An SQL injection vulnerability has been reported to affect Video Station. An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Video Station 5.8.2 and later NVD description · AI analysis pending | 0.1 | <1% |
| — | ||
| CVE-2025-62853 | A path traversal vulnerability has been reported to affect File Station 5. A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5166 and later NVD description · AI analysis pending | 5.2 group max | <1% |
| — | ||
| CVE-2025-68406 | A path traversal vulnerability has been reported to affect Qsync Central. A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later NVD description · AI analysis pending | 1.3 group max | <1% |
| — | ||
| CVE-2025-66277 | A link following vulnerability has been reported to affect several QNAP operating system versions. A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3350 build 20251216 and later QuTS hero h5.3.2.3354 build 20251225 and later QuTS hero h5.2.8.3350 build 20251216 and later NVD description · AI analysis pending | 9.2 | <1% |
| — | ||
| CVE-2025-66274 +1 in the same advisory: …59386 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.2.3354 build 20251225 and later QuTS hero h6.0.0.3397 build 20260206 and later NVD description · AI analysis pending | 5.1 group max | <1% |
| — |