Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
| CVE | Vendor | Product | Vulnerability | CVSS | Added | Due per BOD 22-01 | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2023-47565 | QNAP | VioStor NVR | QNAP VioStor NVR OS Command Injection Vulnerability QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network. | 8.0 CNA | 2023-12-21 | 2024-01-11 | Unknown |
| CVE-2022-27593 | QNAP | Photo Station | QNAP Photo Station Externally Controlled Reference Vulnerability Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign. | 10.0 CNA | 2022-09-08 | 2022-09-29 | Known |
| CVE-2019-7192 | QNAP | Photo Station | QNAP Photo Station Improper Access Control Vulnerability QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system. | 9.8 CISA | 2022-06-08 | 2022-06-22 | Known |
| CVE-2019-7193 | QNAP | QTS | QNAP QTS Improper Input Validation Vulnerability QNAP QTS contains an improper input validation vulnerability allowing remote attackers to inject code on the system. | 9.8 CISA | 2022-06-08 | 2022-06-22 | Known |
| CVE-2019-7194 | QNAP | Photo Station | QNAP Photo Station Path Traversal Vulnerability QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. | 9.8 CISA | 2022-06-08 | 2022-06-22 | Known |
| CVE-2019-7195 | QNAP | Photo Station | QNAP Photo Station Path Traversal Vulnerability QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. | 9.8 CISA | 2022-06-08 | 2022-06-22 | Known |
| CVE-2018-19943 | QNAP | Network Attached Storage (NAS) | QNAP NAS File Station Cross-Site Scripting Vulnerability A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. | 8.0 CNA | 2022-05-24 | 2022-06-14 | Known |
| CVE-2018-19949 | QNAP | Network Attached Storage (NAS) | QNAP NAS File Station Command Injection Vulnerability A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands. | 9.8 CISA | 2022-05-24 | 2022-06-14 | Known |
| CVE-2018-19953 | QNAP | Network Attached Storage (NAS) | QNAP NAS File Station Cross-Site Scripting Vulnerability A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. | 6.1 CISA | 2022-05-24 | 2022-06-14 | Known |
| CVE-2020-2509 | QNAP | QNAP Network-Attached Storage (NAS) | QNAP Network-Attached Storage (NAS) Command Injection Vulnerability QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution. | 9.8 CISA | 2022-04-11 | 2022-05-02 | Unknown |
| CVE-2021-28799 | QNAP | Network Attached Storage (NAS) | QNAP NAS Improper Authorization Vulnerability QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device. | 10.0 CNA | 2022-03-31 | 2022-04-21 | Known |