Qnap Security Vulnerabilities (CVEs)

Track 240 security vulnerabilities affecting Qnap products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

39 Critical
88 High
112 Medium
1 Low
🔔 Get Alerts for Qnap
CVE-2025-53590 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Jan 2, 2026
CVE-2025-53591 6.5

A format string vulnerability in QNAP operating systems allows attackers with administrator access to read sensitive data or modify memory. This affec...

Jan 2, 2026
CVE-2025-53592 6.5

A NULL pointer dereference vulnerability in QNAP operating systems allows authenticated remote attackers to cause denial-of-service conditions. This a...

Jan 2, 2026
CVE-2025-47208 6.5

This CVE describes a resource exhaustion vulnerability in QNAP operating systems where authenticated remote attackers can allocate resources without l...

Jan 2, 2026
CVE-2025-52426 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Jan 2, 2026
CVE-2025-52430 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Jan 2, 2026
CVE-2025-52431 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Jan 2, 2026
CVE-2025-52863 8.1

A buffer overflow vulnerability in QNAP operating systems allows authenticated remote attackers to modify memory or crash processes. This affects QNAP...

Jan 2, 2026
CVE-2025-52864 8.1

A buffer overflow vulnerability in QNAP operating systems allows authenticated remote attackers to modify memory or crash processes. This affects user...

Jan 2, 2026
CVE-2025-52872 8.1

A buffer overflow vulnerability in QNAP operating systems allows authenticated remote attackers to modify memory or crash processes. This affects user...

Jan 2, 2026
CVE-2025-44013 6.5

A NULL pointer dereference vulnerability in QNAP operating systems allows authenticated remote attackers to cause denial-of-service conditions. This a...

Jan 2, 2026
CVE-2025-59385 9.8

This CVE describes an authentication bypass vulnerability in QNAP operating systems that allows remote attackers to spoof authentication and access re...

Dec 16, 2025
CVE-2025-62847 7.5

This CVE describes an argument injection vulnerability in QNAP operating systems where attackers can manipulate command arguments to alter execution l...

Dec 16, 2025
CVE-2025-62849 9.8

This SQL injection vulnerability in QNAP operating systems allows remote attackers to execute arbitrary SQL commands. If exploited, attackers could ex...

Dec 16, 2025
CVE-2017-20210 9.8

This vulnerability in QNAP Photo Station allowed unauthorized cryptocurrency mining (XMR mining) through security weaknesses. It affects QNAP NAS devi...

Nov 11, 2025
CVE-2025-58464 7.5

A relative path traversal vulnerability in QuMagie allows remote attackers to read arbitrary files on the system. This affects all QuMagie installatio...

Nov 7, 2025
CVE-2025-58469 8.8

A cross-site request forgery (CSRF) vulnerability in QuLog Center allows attackers to trick authenticated users into performing unintended actions. Th...

Nov 7, 2025
CVE-2025-54168 4.8

A stored cross-site scripting (XSS) vulnerability in QuLog Center allows authenticated attackers with administrator privileges to inject malicious scr...

Nov 7, 2025
CVE-2025-57712 6.5

A path traversal vulnerability in Qsync Central allows authenticated attackers to read arbitrary files on the system. This affects all Qsync Central i...

Nov 7, 2025
CVE-2025-53408 6.5

A NULL pointer dereference vulnerability in QNAP File Station 5 allows authenticated attackers to cause denial-of-service by crashing the service. Thi...

Nov 7, 2025
CVE-2025-53410 6.5

This vulnerability in QNAP File Station 5 allows authenticated remote attackers to exhaust system resources, potentially causing denial-of-service con...

Nov 7, 2025
CVE-2025-53412 6.5

A NULL pointer dereference vulnerability in QNAP File Station 5 allows authenticated remote attackers to cause denial-of-service by crashing the servi...

Nov 7, 2025
CVE-2025-47207 6.5

A NULL pointer dereference vulnerability in QNAP File Station allows authenticated attackers to cause denial-of-service conditions. This affects users...

Nov 7, 2025
CVE-2025-52425 9.8

An SQL injection vulnerability in QuMagie allows remote attackers to execute arbitrary SQL commands. This affects all QuMagie installations before ver...

Nov 7, 2025
CVE-2025-57714 7.8

An unquoted search path vulnerability in NetBak Replicator allows local attackers with user accounts to execute arbitrary code by placing malicious ex...

Oct 3, 2025
CVE-2025-52862 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Oct 3, 2025
CVE-2025-52867 6.5

An uncontrolled resource consumption vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This ...

Oct 3, 2025
CVE-2025-53407 6.5

A format string vulnerability in QNAP operating systems allows attackers with administrator access to read sensitive data or modify memory. This affec...

Oct 3, 2025
CVE-2025-53595 8.8

An SQL injection vulnerability in Qsync Central allows authenticated attackers to execute arbitrary SQL commands. This could lead to unauthorized data...

Oct 3, 2025
CVE-2025-54153 8.8

An SQL injection vulnerability in Qsync Central allows authenticated remote attackers to execute arbitrary SQL commands. This could lead to unauthoriz...

Oct 3, 2025
CVE-2025-52854 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Oct 3, 2025
CVE-2025-52857 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Oct 3, 2025
CVE-2025-52859 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Oct 3, 2025
CVE-2025-52432 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Oct 3, 2025
CVE-2025-52853 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Oct 3, 2025
CVE-2025-48729 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Oct 3, 2025
CVE-2025-52424 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Oct 3, 2025
CVE-2025-52428 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Oct 3, 2025
CVE-2025-47214 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Oct 3, 2025
CVE-2025-48727 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Oct 3, 2025
CVE-2025-44014 8.8

An out-of-bounds write vulnerability in Qsync Central allows authenticated remote attackers to modify or corrupt memory. This affects QNAP Qsync Centr...

Oct 3, 2025
CVE-2025-47211 4.9

A path traversal vulnerability in QNAP operating systems allows authenticated attackers with administrator privileges to read arbitrary files. This af...

Oct 3, 2025
CVE-2025-47212 7.2

A command injection vulnerability in QNAP operating systems allows authenticated attackers with administrator privileges to execute arbitrary commands...

Oct 3, 2025
CVE-2025-44008 6.5

A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service by crashing the service. Th...

Oct 3, 2025
CVE-2025-44010 6.5

A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This affects al...

Oct 3, 2025
CVE-2025-44012 6.5

A resource exhaustion vulnerability in Qsync Central allows authenticated attackers to consume system resources, potentially causing denial of service...

Oct 3, 2025
CVE-2025-33040 6.5

This vulnerability in Qsync Central allows authenticated remote attackers to allocate resources without limits, potentially causing denial of service ...

Oct 3, 2025
CVE-2025-44006 6.5

This vulnerability in Qsync Central allows authenticated remote attackers to perform resource exhaustion attacks by allocating resources without limit...

Oct 3, 2025
CVE-2024-56804 8.8

This SQL injection vulnerability in QNAP Video Station allows authenticated attackers to execute arbitrary SQL commands. Attackers with user accounts ...

Oct 3, 2025
CVE-2025-33039 6.5

This vulnerability in Qsync Central allows authenticated remote attackers to exhaust system resources through unlimited allocation, potentially causin...

Oct 3, 2025

Why Monitor Qnap Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 240+ known vulnerabilities affecting Qnap products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Qnap packages in under 60 seconds. No agents required - completely agentless scanning that works across Qnap deployments.

Free vulnerability database: Access detailed information about every Qnap CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Qnap CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Qnap CVEs Free