Qnap
Qnap Video Station: vulnerabilidades y CVE
Qnap Video Station tiene 15 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses3
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-14025 | Baja (0.1) | 0.14% | — | 11 mar 2026 | An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute… |
| CVE-2024-14024 | Baja (0.1) | 0.08% | — | 11 mar 2026 | An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the… |
| CVE-2024-56804 | Media (5.3) | 0.37% | — | 3 oct 2025 | An SQL injection vulnerability has been reported to affect Video Station. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already… |
| CVE-2023-50360 | Alta (8.8) | 0.44% | — | 6 sept 2024 | A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in… |
| CVE-2023-47563 | Alta (8.8) | 0.97% | — | 6 sept 2024 | An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability… |
| CVE-2023-41288 | Alta (8.8) | 1.1% | — | 5 ene 2024 | An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the… |
| CVE-2023-41287 | Alta (8.8) | 0.51% | — | 5 ene 2024 | A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to inject malicious code via a network. We have already fixed the vulnerability in the following… |
| CVE-2023-34977 | Media (5.4) | 0.30% | — | 13 oct 2023 | A cross-site scripting (XSS) vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the… |
| CVE-2023-34976 | Alta (8.8) | 0.51% | — | 13 oct 2023 | A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in… |
| CVE-2023-34975 | Alta (8.8) | 1.0% | — | 13 oct 2023 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.… |
| CVE-2021-44056 | Crítica (9.8) | 0.93% | — | 5 may 2022 | An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed… |
| CVE-2021-44055 | Crítica (9.8) | 1.1% | — | 5 may 2022 | An missing authorization vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows remote attackers to access data or perform actions that they should not be… |
| CVE-2021-28812 | Alta (8.8) | 1.6% | — | 3 jun 2021 | A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems… |
| CVE-2019-7184 | Media (4.8) | 1.5% | — | 5 dic 2019 | This cross-site scripting (XSS) vulnerability in Video Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Video… |
| CVE-2017-13071 | Crítica (9.8) | 1.4% | — | 22 nov 2017 | QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on the QNAP Video Station 5.1.3 (for QTS 4.3.3), 5.2.0 (for QTS 4.3.4), and earlier. |