Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (0.1) | 0.14% | — | Qnap Video Station | 11/3/2026 | 17/6/2026 | An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Video… | |
| Analizada | Baja (0.1) | 0.08% | — | Qnap Video Station | 11/3/2026 | 17/6/2026 | An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following… | |
| Analizada | Media (5.3) | 0.37% | — | Qnap Video Station | 3/10/2025 | 17/6/2026 | An SQL injection vulnerability has been reported to affect Video Station. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Video Station 5.8.4 and later | |
| Analizada | Alta (8.8) | 0.44% | — | Qnap Video Station | 6/9/2024 | 17/6/2026 | A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.8.1 ( 2024/02/26 ) and later | |
| Analizada | Alta (8.8) | 0.97% | — | Qnap Video Station | 6/9/2024 | 17/6/2026 | An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: Video Station 5.8.2 and later | |
| Modificada | Alta (8.8) | 1.1% | — | Qnap Video Station | 5/1/2024 | 17/6/2026 | An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.2 ( 2023/11/23 ) and later | |
| Modificada | Alta (8.8) | 0.51% | — | Qnap Video Station | 5/1/2024 | 17/6/2026 | A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.2 ( 2023/11/23 ) and later | |
| Modificada | Media (5.4) | 0.30% | — | Qnap Video Station | 13/10/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.0 ( 2023/07/27 ) and later | |
| Modificada | Alta (8.8) | 0.51% | — | Qnap Video Station | 13/10/2023 | 17/6/2026 | A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.0 ( 2023/07/27 ) and later | |
| Modificada | Alta (8.8) | 1.0% | — | Qnap Video Station | 13/10/2023 | 17/6/2026 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. QuTScloud is not affected. We have already fixed the vulnerability in the following versions: QuTS hero… | |
| Modificada | Crítica (9.8) | 0.93% | — | Qnap Video Station | 5/5/2022 | 17/6/2026 | An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Video Station: Video Station 5.5.9 and later Video… | |
| Modificada | Crítica (9.8) | 1.1% | — | Qnap Video Station | 5/5/2022 | 17/6/2026 | An missing authorization vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows remote attackers to access data or perform actions that they should not be allowed to perform. We have already fixed this vulnerability in the following versions of Video… | |
| Modificada | Alta (8.8) | 1.6% | — | Qnap Video Station | 3/6/2021 | 17/6/2026 | A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Video Station versions prior to 5.5.4 on QTS 4.5.2; versions prior to 5.5.4 on QuTS hero h4.5.2;… | |
| Modificada | Crítica (9.1) | 0.97% | — | Synology Video Station | 1/6/2021 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station before 2.4.10-1632 allows remote authenticated users to send arbitrary request to intranet resources via unspecified vectors. | |
| Modificada | Media (4.8) | 1.5% | — | Qnap Video Station | 5/12/2019 | 17/6/2026 | This cross-site scripting (XSS) vulnerability in Video Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Video Station to their latest versions. | |
| Modificada | Crítica (9.8) | 1.4% | — | Qnap Video Station | 22/11/2017 | 17/6/2026 | QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on the QNAP Video Station 5.1.3 (for QTS 4.3.3), 5.2.0 (for QTS 4.3.4), and earlier. | |
| Modificada | Media (5.4) | 0.79% | — | Synology Video Station | 11/8/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Video Metadata Editor in Synology Video Station before 2.3.0-1435 allows remote authenticated attackers to inject arbitrary web script or HTML via the title parameter. | |
| Modificada | Media (5.4) | 0.82% | — | Synology Video Station | 30/6/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, and 1.6 before 1.6-0847 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) file name or (2) collection name of videos. | |
| Modificada | Alta (10) | 12% | — | Synology Video Station | 11/9/2015 | 17/6/2026 | Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharacters in the subtitle_codepage parameter to subtitle.cgi. | |
| Modificada | Alta (7.5) | 2.4% | — | Synology Video Station | 11/9/2015 | 17/6/2026 | SQL injection vulnerability in Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary SQL commands via the id parameter to watchstatus.cgi. | |
| Modificada | Alta (7.5) | 2.3% | — | Synology Video Station | 11/9/2015 | 17/6/2026 | SQL injection vulnerability in Synology Video Station before 1.5-0757 allows remote attackers to execute arbitrary SQL commands via the id parameter to audiotrack.cgi. |