CameraRisk

QNAP QVR

cpe:2.3:*:qnap:qvr

Vendor
QNAP
Device type
Video management software
Published vulnerabilities
11
In CISA KEV
1 KEV
Affected versions recorded
7
Data last built
5 September 2026

Security summary

11 published vulnerabilities affect this product according to NVD. 1 of them is in CISA's Known Exploited Vulnerabilities catalogue, which means confirmed exploitation in the wild.

Exploited: CVE-2023-47565.

Experimental risk indicator

Components are shown separately and deliberately not combined into a single number. Two of the six inputs below have no public source for any product on this site; a composite built without them would be a guess wearing a decimal point.

Known vulnerability count 11 bar scaled to 20
Highest published severity 9.8 CRITICAL
Confirmed exploitation yes 1 in CISA KEV
Exploitation probability EPSS 73.3% (highest)
Lifecycle status no source
Deployed exposure not measurable from public data

Published vulnerabilities

CVEPublishedCVSS SeverityEPSSFlags
CVE-2025-52856 2025-08-29 9.3 critical 0.6% Vendor advisory
CVE-2023-47565 2023-12-08 8.8 high 73.3% KEVVendor advisory
CVE-2022-27597 2023-03-29 2.7 low 0.7% Vendor advisory
CVE-2023-23355 2023-03-29 7.2 high 1.2% Vendor advisory
CVE-2022-27588 2022-05-05 9.8 critical 1.3% Vendor advisory
CVE-2021-38686 2021-11-26 8.8 high 0.9% Vendor advisory
CVE-2021-38685 2021-11-26 9.8 critical 1.5% Vendor advisory
CVE-2021-34352 2021-10-01 9.8 critical 1.5% Vendor advisory
CVE-2021-34351 2021-09-27 9.8 critical 1.5% Vendor advisory
CVE-2021-34349 2021-09-27 7.2 high 1.5% Vendor advisory
CVE-2021-34348 2021-09-27 9.8 critical 1.5% Vendor advisory

Affected versions

Version strings recorded by NVD against this product. These are the versions named in CPE match rules, not a complete firmware history — a version absent here has not been cleared, it has simply never been named in a CVE record.

5.1.6

Ranges: < 5.0.0 · < 5.1.5 · < 5.1.6 · <= 5.1.6 · >= 4.0.0 · >= 5.1.0

What this page does not tell you

There is no public dataset of end-of-support dates, default credentials or shipped network services for this product, so those fields are absent rather than estimated. Whether any of these vulnerabilities is exploitable in your deployment depends on firmware version, configuration and network position — none of which is knowable from here.

For the vendor's own advisories, see QNAP.

Other QNAP products

Vulnerability records from the National Vulnerability Database, matched to this product by CPE. Exploitation status from CISA KEV 2026.09.04. Exploitation probability from FIRST EPSS, 2026-09-04. Product name derived mechanically from the CPE identifier. See methodology.