| CVE-2026-44083 | 9.8 | critical | qumagie | An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. | 88d ago |
| CVE-2026-22901 | 9.8 | critical | qunetswitch | A command injection vulnerability has been reported to affect QuNetSwitch. | 169d ago |
| CVE-2025-59388 | 9.8 | critical | hyper data protector | A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. | 178d ago |
| CVE-2025-66276 | 9.8 | critical | qts | QuTS hero is not affected. | 88d ago |
| CVE-2026-22897 | 9.8 | critical | qunetswitch | A command injection vulnerability has been reported to affect QuNetSwitch. | 169d ago |
| CVE-2026-22898 | 9.8 | critical | qvr pro | A missing authentication for critical function vulnerability has been reported to affect QVR Pro. | 169d ago |
| CVE-2026-22900 | 9.8 | critical | qunetswitch | A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. | 169d ago |
| CVE-2026-26241 | 9.1 | critical | file station | A buffer overflow vulnerability has been reported to affect File Station 5. | 87d ago |
| CVE-2025-59383 | 9.1 | critical | media streaming add-on | A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. | 169d ago |
| CVE-2026-26240 | 9.1 | critical | file station | A buffer overflow vulnerability has been reported to affect File Station 5. | 87d ago |
| CVE-2025-58468 | 8.8 | high | notification center | A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. | 88d ago |
| CVE-2026-24724 | 8.1 | high | file station | An incorrect authorization vulnerability has been reported to affect File Station 6. | 88d ago |
| CVE-2026-26239 | 8.1 | high | file station | A buffer overflow vulnerability has been reported to affect File Station 5. | 88d ago |
| CVE-2026-26236 | 7.5 | high | qumagie | A missing authorization vulnerability has been reported to affect QuMagie. | 88d ago |
| CVE-2026-26237 | 7.5 | high | qumagie | A missing authorization vulnerability has been reported to affect QuMagie. | 88d ago |
| CVE-2025-66281 | 7.2 | high | qts | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. | 88d ago |
| CVE-2026-22893 | 7.2 | high | qts | A command injection vulnerability has been reported to affect several QNAP operating system versions. | 88d ago |
| CVE-2026-24716 | 7.2 | high | qts | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. | 88d ago |
| CVE-2026-24719 | 7.2 | high | qts | A command injection vulnerability has been reported to affect several QNAP operating system versions. | 88d ago |
| CVE-2025-62850 | 7.2 | high | quts hero | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. | 88d ago |
| CVE-2025-66273 | 7.2 | high | qts | A command injection vulnerability has been reported to affect several QNAP operating system versions. | 88d ago |
| CVE-2025-66279 | 7.2 | high | qts | A command injection vulnerability has been reported to affect several QNAP operating system versions. | 88d ago |
| CVE-2025-66280 | 7.2 | high | qts | An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions | 88d ago |
| CVE-2025-62843 | 6.8 | medium | qurouter | An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect Q | 169d ago |
| CVE-2025-62845 | 6.7 | medium | qurouter | An improper neutralization of escape, meta, or control sequences vulnerability has been reported to affect QHora. | 169d ago |
| CVE-2026-22902 | 6.7 | medium | qunetswitch | A command injection vulnerability has been reported to affect QuNetSwitch. | 169d ago |
| CVE-2025-62846 | 6.7 | medium | qurouter | An SQL injection vulnerability has been reported to affect QHora. | 169d ago |
| CVE-2025-62844 | 5.5 | medium | qurouter | A weak authentication vulnerability has been reported to affect QHora. | 169d ago |
| CVE-2026-22895 | 4.8 | medium | quftp | A cross-site scripting (XSS) vulnerability has been reported to affect QuFTP Service. | 169d ago |