Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.34% | — | Qnap Photo Station | 11/11/2025 | 17/6/2026 | Photo Station 5.4.1 & 5.2.7 include the security fix for the vulnerability related to the XMR mining programs identified by internal research. | |
| Analizada | Baja (2) | 0.24% | — | Qnap Photo Station | 29/8/2025 | 26/9/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following version: Photo Station 6.4.5 (… | |
| Analizada | Media (5.4) | 0.37% | — | Qnap Photo Station | 22/11/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already fixed the vulnerability in the following version: Photo Station 6.4.3 ( 2024/07/12 ) and later | |
| Analizada | Media (5.4) | 0.37% | — | Qnap Photo Station | 22/11/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already fixed the vulnerability in the following version: Photo Station 6.4.3 ( 2024/07/12 ) and later | |
| Analizada | Media (5.4) | 0.37% | — | Qnap Photo Station | 22/11/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already fixed the vulnerability in the following version: Photo Station 6.4.3 ( 2024/07/12 ) and later | |
| Analizada | Media (5.4) | 0.37% | — | Qnap Photo Station | 22/11/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already fixed the vulnerability in the following version: Photo Station 6.4.3 ( 2024/07/12 ) and later | |
| Analizada | Media (4.9) | 0.45% | — | Qnap Photo Station | 8/3/2024 | 17/6/2026 | A path traversal vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following version: Photo Station 6.4.2 (… | |
| Modificada | Alta (8.8) | 1.1% | — | Qnap Photo Station | 2/2/2024 | 17/6/2026 | An OS command injection vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15 ) and later | |
| Modificada | Media (5.4) | 0.26% | — | Qnap Photo Station | 2/2/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15 ) and later | |
| Analizada | Crítica (9.1) | 88% | ⚠ Explotación activa | Qnap Photo Station | 8/9/2022 | 17/6/2026 | An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x:… | |
| Modificada | Alta (7.5) | 1.0% | — | Synology Photo Station | 6/7/2022 | 17/6/2026 | Session fixation vulnerability in access control management in Synology Photo Station before 6.8.16-3506 allows remote attackers to bypass security constraint via unspecified vectors. | |
| Modificada | Crítica (9.8) | 0.93% | — | Qnap Photo Station | 5/5/2022 | 17/6/2026 | An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.20 ( 2022/02/15 )… | |
| Modificada | Media (5.4) | 0.65% | — | Qnap Photo Station | 1/10/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.18 ( 2021/09/01 ) and later | |
| Modificada | Media (5.4) | 0.65% | — | Qnap Photo Station | 1/10/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 5.4.10 ( 2021/08/19 ) and later… | |
| Modificada | Media (5.4) | 0.65% | — | Qnap Photo Station | 1/10/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.18 ( 2021/09/01 ) and later | |
| Modificada | Crítica (9.8) | 1.9% | — | Synology Photo Station | 2/6/2021 | 17/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in thumbnail component in Synology Photo Station before 6.8.14-3500 allows remote attackers users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.5) | 1.1% | — | Synology Photo Station | 2/6/2021 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to write arbitrary files via unspecified vectors. | |
| Modificada | Alta (7.2) | 1.7% | — | Synology Photo Station | 2/6/2021 | 17/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in PHP component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary SQL command via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.7% | — | Synology Photo Station | 1/6/2021 | 17/6/2026 | Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (6.1) | 0.83% | — | Qnap Photo Station | 17/2/2021 | 17/6/2026 | This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. Photo Station 6.0.11 and later | |
| Modificada | Media (6.1) | 0.99% | — | Qnap Photo Station | 10/12/2020 | 17/6/2026 | This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. QTS 4.5.1: Photo Station 6.0.12 and later QTS 4.4.3: Photo Station 6.0.12 and later QTS 4.3.6: Photo Station 5.7.12 and… | |
| Modificada | Media (6.1) | 0.92% | — | Qnap Photo Station | 2/11/2020 | 17/6/2026 | The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10. | |
| Modificada | Media (6.1) | 0.92% | — | Qnap Photo Station | 2/11/2020 | 17/6/2026 | The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10. | |
| Modificada | Media (6.1) | 0.92% | — | Qnap Photo Station | 2/11/2020 | 17/6/2026 | The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10. | |
| Analizada | Crítica (9.8) | 90% | ⚠ Explotación activa | Qnap Photo Station | 5/12/2019 | 17/6/2026 | This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions. |