cve,link,title,description,vendor,products,score,severity,epss,cisa,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2023-47221,https://securityvulnerability.io/vulnerability/CVE-2023-47221,Photo Station Vulnerability: Authenticated Admins at Risk of Exposing Sensitive Data,"A path traversal vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15 ) and later ",QNAP,Photo Station,5.5,MEDIUM,0.0004400000034365803,false,false,false,false,,false,false,2024-03-08T16:15:23.594Z,0 CVE-2023-47562,https://securityvulnerability.io/vulnerability/CVE-2023-47562,Photo Station,"An OS command injection vulnerability has been identified in Photo Station, a multimedia management software developed by QNAP. This vulnerability could be exploited by authenticated users to execute arbitrary commands on the server through network requests. The issue poses a significant risk, as it enables attackers to manipulate the operating system and potentially gain unauthorized access to sensitive information or system functionalities. QNAP has addressed this vulnerability in Photo Station version 6.4.2, released on December 15, 2023, and urges users to upgrade to this version or later to mitigate potential risks.",QNAP,Photo Station,7.4,HIGH,0.0006000000284984708,false,false,false,false,,false,false,2024-02-02T16:05:48.610Z,0 CVE-2023-47561,https://securityvulnerability.io/vulnerability/CVE-2023-47561,Photo Station,"A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15 ) and later ",QNAP,Photo Station,5.5,MEDIUM,0.0004799999878741801,false,false,false,false,,false,false,2024-02-02T16:05:42.663Z,0 CVE-2022-27593,https://securityvulnerability.io/vulnerability/CVE-2022-27593,DeadBolt Ransomware,"An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later",QNAP,Photo Station,10,CRITICAL,0.4184899926185608,true,false,true,true,,false,false,2022-09-08T00:00:00.000Z,0 CVE-2021-44057,https://securityvulnerability.io/vulnerability/CVE-2021-44057,Improper authentication in Photo Station,"An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.20 ( 2022/02/15 ) and later Photo Station 5.7.16 ( 2022/02/11 ) and later Photo Station 5.4.13 ( 2022/02/11 ) and later",QNAP,Photo Station,7.1,HIGH,0.002520000096410513,false,false,false,false,,false,false,2022-05-05T17:15:00.000Z,0 CVE-2021-34354,https://securityvulnerability.io/vulnerability/CVE-2021-34354,Stored Cross-site Scripting Vulnerability in Photo Station,"A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.18 ( 2021/09/01 ) and later",QNAP,Photo Station,7.6,HIGH,0.0006600000197067857,false,false,false,false,,false,false,2021-10-01T00:00:00.000Z,0 CVE-2021-34356,https://securityvulnerability.io/vulnerability/CVE-2021-34356,Stored XSS Vulnerability in Photo Station,"A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.18 ( 2021/09/01 ) and later",QNAP,Photo Station,7.6,HIGH,0.0006600000197067857,false,false,false,false,,false,false,2021-10-01T00:00:00.000Z,0 CVE-2021-34355,https://securityvulnerability.io/vulnerability/CVE-2021-34355,Stored XSS Vulnerability in Photo Station,"A cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 5.4.10 ( 2021/08/19 ) and later Photo Station 5.7.13 ( 2021/08/19 ) and later Photo Station 6.0.18 ( 2021/09/01 ) and later",QNAP,Photo Station,7.6,HIGH,0.0006600000197067857,false,false,false,false,,false,false,2021-10-01T00:00:00.000Z,0 CVE-2020-2502,https://securityvulnerability.io/vulnerability/CVE-2020-2502,Cross-site Scripting Vulnerability in Photo Station,This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. Photo Station 6.0.11 and later,QNAP,Photo Station,6.1,MEDIUM,0.0011500000255182385,false,false,false,false,,false,false,2021-02-17T00:00:00.000Z,0 CVE-2020-2491,https://securityvulnerability.io/vulnerability/CVE-2020-2491,Cross-site Scripting Vulnerability in Photo Station,This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. QTS 4.5.1: Photo Station 6.0.12 and later QTS 4.4.3: Photo Station 6.0.12 and later QTS 4.3.6: Photo Station 5.7.12 and later QTS 4.3.4: Photo Station 5.7.13 and later QTS 4.3.3: Photo Station 5.4.10 and later QTS 4.2.6: Photo Station 5.2.11 and later,QNAP,Photo Station,6.1,MEDIUM,0.0011500000255182385,false,false,false,false,,false,false,2020-12-07T00:00:00.000Z,0 CVE-2018-19956,https://securityvulnerability.io/vulnerability/CVE-2018-19956,,"The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10.",QNAP,Photo Station,6.1,MEDIUM,0.0011500000255182385,false,false,false,false,,false,false,2020-11-02T16:15:00.000Z,0 CVE-2018-19954,https://securityvulnerability.io/vulnerability/CVE-2018-19954,,"The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10.",QNAP,Photo Station,6.1,MEDIUM,0.0011500000255182385,false,false,false,false,,false,false,2020-11-02T16:15:00.000Z,0 CVE-2018-19955,https://securityvulnerability.io/vulnerability/CVE-2018-19955,,"The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10.",QNAP,Photo Station,6.1,MEDIUM,0.0011500000255182385,false,false,false,false,,false,false,2020-11-02T16:15:00.000Z,0 CVE-2019-7195,https://securityvulnerability.io/vulnerability/CVE-2019-7195,,"This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.",Qnap,Qnap Nas Devices Running Photo Station,9.8,CRITICAL,0.9686200022697449,true,false,true,true,,false,false,2019-12-05T16:34:38.000Z,0 CVE-2019-7194,https://securityvulnerability.io/vulnerability/CVE-2019-7194,,"This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.",Qnap,Qnap Nas Devices Running Photo Station,9.8,CRITICAL,0.9686200022697449,true,false,true,true,,false,false,2019-12-05T16:30:53.000Z,0 CVE-2019-7192,https://securityvulnerability.io/vulnerability/CVE-2019-7192,,"This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.",Qnap,Qnap Nas Devices Running Photo Station,9.8,CRITICAL,0.9524199962615967,true,false,true,true,true,false,false,2019-12-05T16:17:29.000Z,0 CVE-2018-0722,https://securityvulnerability.io/vulnerability/CVE-2018-0722,,"Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier in QTS 4.2.6 could allow remote attackers to access sensitive information on the device.",Qnap,Photo Station,7.5,HIGH,0.0031999999191612005,false,false,false,false,,false,false,2019-02-01T18:29:00.000Z,0 CVE-2018-0715,https://securityvulnerability.io/vulnerability/CVE-2018-0715,,Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application.,Qnap,Photo Station,6.1,MEDIUM,0.009229999966919422,false,false,false,false,,false,false,2018-08-27T13:29:00.000Z,0 CVE-2017-13073,https://securityvulnerability.io/vulnerability/CVE-2017-13073,,"Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.",Qnap,Photo Station,6.1,MEDIUM,0.0013099999632686377,false,false,false,false,,false,false,2018-04-23T00:00:00.000Z,0 CVE-2013-5760,https://securityvulnerability.io/vulnerability/CVE-2013-5760,,QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to photo/p/api/list.php.,Qnap,"Photo Station Firmware,Photo Station",,,0.00395999988541007,false,false,false,false,,false,false,2014-06-09T19:00:00.000Z,0