QNAP: CISA KEV History
Every QNAP vulnerability in the CISA Known Exploited Vulnerabilities catalog: confirmed in-the-wild exploitation, addition timeline, and ransomware linkage. Rebuilt automatically on every site deploy.
Snapshot: 2026-09-08 · Source: CISA KEV Catalog · Full KEV dashboard
KEV entries
11
Added, last 12 months
0
Ransomware-linked
9
Latest addition
2023-12-21
QNAP KEV additions per month, last 24 months
Most-listed products: Photo Station, Network Attached Storage (NAS), VioStor NVR, QTS, QNAP Network-Attached Storage (NAS).
Latest 11 of 11 QNAP KEV entries
| CVE | Vulnerability | Added | Ransomware |
|---|---|---|---|
| CVE-2023-47565 | QNAP VioStor NVR OS Command Injection Vulnerability | 2023-12-21 | No |
| CVE-2022-27593 | QNAP Photo Station Externally Controlled Reference Vulnerability | 2022-09-08 | Yes |
| CVE-2019-7195 | QNAP Photo Station Path Traversal Vulnerability | 2022-06-08 | Yes |
| CVE-2019-7194 | QNAP Photo Station Path Traversal Vulnerability | 2022-06-08 | Yes |
| CVE-2019-7193 | QNAP QTS Improper Input Validation Vulnerability | 2022-06-08 | Yes |
| CVE-2019-7192 | QNAP Photo Station Improper Access Control Vulnerability | 2022-06-08 | Yes |
| CVE-2018-19953 | QNAP NAS File Station Cross-Site Scripting Vulnerability | 2022-05-24 | Yes |
| CVE-2018-19949 | QNAP NAS File Station Command Injection Vulnerability | 2022-05-24 | Yes |
| CVE-2018-19943 | QNAP NAS File Station Cross-Site Scripting Vulnerability | 2022-05-24 | Yes |
| CVE-2020-2509 | QNAP Network-Attached Storage (NAS) Command Injection Vulnerability | 2022-04-11 | No |
| CVE-2021-28799 | QNAP NAS Improper Authorization Vulnerability | 2022-03-31 | Yes |
CVE links go to our explainer when one exists, otherwise to the NVD record.
Data: official CISA KEV catalog, fetched at build time. Figures may be reused with attribution to East Bay Cyber and CISA. See also the KEV Velocity Dashboard and all tracked vendors.