Product
qnap video station
21 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-14025
CVE-2024-14024
CVE-2024-56804
CVE-2023-50360
CVE-2023-47563
CVE-2023-41288
CVE-2023-41287
CVE-2023-34977
CVE-2023-34976
CVE-2023-34975
CVE-2021-44056
CVE-2021-44055
CVE-2021-28812
CVE-2021-33181
CVE-2019-7184
CVE-2017-13071
CVE-2017-9556
CVE-2015-9105
CVE-2015-6912
CVE-2015-6911
CVE-2015-6910
>= 5.0.0 and < 5.8.2
An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also
>= 5.0.0 and < 5.8.2
An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local network acc
>= 5.8.0 and < 5.8.4
An SQL injection vulnerability has been reported to affect Video Station. If a remote attacker gains a user account, they can then
>= 5.0.0 and < 5.8.2
A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated
>= 5.0.0 and < 5.8.2
An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authe
>= 5.7.0 and < 5.7.2
An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users
>= 5.7.0 and < 5.7.2
A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to inje
< 2023.07.27
A cross-site scripting (XSS) vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow
< 5.7.0
A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated
< 5.7.0
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulner
< 5.1.8
An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnera
< 5.1.8
An missing authorization vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerabi
< 5.5.4
A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability
< 2.4.10-1632
Server-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station before 2.4.10-1632 allows remote au
< 5.4.3
This cross-site scripting (XSS) vulnerability in Video Station allows remote attackers to inject and execute scripts on the admini
all versions
QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on the QNAP
<= 2.2.1-1364
Cross-site scripting (XSS) vulnerability in Video Metadata Editor in Synology Video Station before 2.3.0-1435 allows remote authen
all versions
Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, and 1.6 be
<= 1.5-0757
Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharacters in the
<= 1.5-0757
SQL injection vulnerability in Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary SQL commands vi
<= 1.5-0754
SQL injection vulnerability in Synology Video Station before 1.5-0757 allows remote attackers to execute arbitrary SQL commands vi