Vendor

QNAP

As of , 11 QNAP vulnerabilities are on CISA's list of exploited vulnerabilities, 9 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2019-7192.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2019-7192Improper Access ControlQNAP Photo StationPatch this weekRansomware use; Metasploit module; EPSS 0.880.88
2CVE-2019-7194Path TraversalQNAP Photo StationPatch this weekRansomware use; Metasploit module; EPSS 0.830.83
3CVE-2019-7195Path TraversalQNAP Photo StationPatch this weekRansomware use; Metasploit module; EPSS 0.900.90
4CVE-2023-47565OS Command InjectionQNAP VioStor NVRPatch this weekEPSS 0.730.73
5CVE-2022-27593Externally Controlled ReferenceQNAP Photo StationPatch this weekRansomware use; EPSS 0.880.88
6CVE-2021-28799NAS Improper AuthorizationQNAP Network Attached Storage (NAS)Patch this weekRansomware use; EPSS 0.780.78
7CVE-2018-19949NAS File Station Command InjectionQNAP Network Attached Storage (NAS)Patch this weekRansomware use0.28
8CVE-2018-19953NAS File Station Cross-Site ScriptingQNAP Network Attached Storage (NAS)Patch this weekRansomware use0.29
9CVE-2018-19943NAS File Station Cross-Site ScriptingQNAP Network Attached Storage (NAS)Patch this weekRansomware use0.21
10CVE-2019-7193Improper Input ValidationQNAP QTSPatch this weekRansomware use0.14
11CVE-2020-2509Command InjectionQNAP QNAP Network-Attached Storage (NAS)Patch soon0.34

Products

Added each year

5102022: 101020222023: 1120232024: nonenone20242025: nonenone20252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
202210
20231
2024none
2025none
2026none

Used in ransomware