Vendor
QNAP
As of , 11 QNAP vulnerabilities are on CISA's list of exploited vulnerabilities, 9 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2019-7192.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2019-7192Improper Access Control | QNAP Photo Station | Patch this weekRansomware use; Metasploit module; EPSS 0.88 | 0.88 | ||
| 2 | CVE-2019-7194Path Traversal | QNAP Photo Station | Patch this weekRansomware use; Metasploit module; EPSS 0.83 | 0.83 | ||
| 3 | CVE-2019-7195Path Traversal | QNAP Photo Station | Patch this weekRansomware use; Metasploit module; EPSS 0.90 | 0.90 | ||
| 4 | CVE-2023-47565OS Command Injection | QNAP VioStor NVR | Patch this weekEPSS 0.73 | 0.73 | ||
| 5 | CVE-2022-27593Externally Controlled Reference | QNAP Photo Station | Patch this weekRansomware use; EPSS 0.88 | 0.88 | ||
| 6 | CVE-2021-28799NAS Improper Authorization | QNAP Network Attached Storage (NAS) | Patch this weekRansomware use; EPSS 0.78 | 0.78 | ||
| 7 | CVE-2018-19949NAS File Station Command Injection | QNAP Network Attached Storage (NAS) | Patch this weekRansomware use | 0.28 | ||
| 8 | CVE-2018-19953NAS File Station Cross-Site Scripting | QNAP Network Attached Storage (NAS) | Patch this weekRansomware use | 0.29 | ||
| 9 | CVE-2018-19943NAS File Station Cross-Site Scripting | QNAP Network Attached Storage (NAS) | Patch this weekRansomware use | 0.21 | ||
| 10 | CVE-2019-7193Improper Input Validation | QNAP QTS | Patch this weekRansomware use | 0.14 | ||
| 11 | CVE-2020-2509Command Injection | QNAP QNAP Network-Attached Storage (NAS) | Patch soon | 0.34 |
Products
- Network Attached Storage (NAS)4 entries
- Photo Station4 entries
- QNAP Network-Attached Storage (NAS)1 entry
- QTS1 entry
- VioStor NVR1 entry
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2022 | 10 |
| 2023 | 1 |
| 2024 | none |
| 2025 | none |
| 2026 | none |