cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2022-22681,https://securityvulnerability.io/vulnerability/CVE-2022-22681,Session Fixation Flaw in Access Control for Synology Photo Station,"A session fixation vulnerability exists in the access control management of Synology Photo Station prior to version 6.8.16-3506. This flaw allows remote attackers to exploit session management by bypassing the established security constraints. Attackers can manipulate session information via unspecified vectors, potentially granting unauthorized access to sensitive user data. Users are urged to update their software to mitigate any risks associated with this vulnerability.",Synology,Photo Station,8.1,HIGH,0.0008299999753944576,false,,false,false,false,,,false,false,,2022-07-06T08:15:00.000Z,0 CVE-2021-29090,https://securityvulnerability.io/vulnerability/CVE-2021-29090,,Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in PHP component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary SQL command via unspecified vectors.,Synology,Synology Photo Station,7.2,HIGH,0.0006799999973736703,false,,false,false,false,,,false,false,,2021-06-02T02:15:00.000Z,0 CVE-2021-29091,https://securityvulnerability.io/vulnerability/CVE-2021-29091,,Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to write arbitrary files via unspecified vectors.,Synology,Synology Photo Station,7.7,HIGH,0.0006300000241026282,false,,false,false,false,,,false,false,,2021-06-02T02:15:00.000Z,0 CVE-2021-29089,https://securityvulnerability.io/vulnerability/CVE-2021-29089,,Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in thumbnail component in Synology Photo Station before 6.8.14-3500 allows remote attackers users to execute arbitrary SQL commands via unspecified vectors.,Synology,Synology Photo Station,9.8,CRITICAL,0.0007399999885819852,false,,false,false,false,,,false,false,,2021-06-02T00:00:00.000Z,0 CVE-2021-29092,https://securityvulnerability.io/vulnerability/CVE-2021-29092,,Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary code via unspecified vectors.,Synology,Synology Photo Station,8.8,HIGH,0.0006799999973736703,false,,false,false,false,,,false,false,,2021-06-01T14:15:00.000Z,0 CVE-2019-11822,https://securityvulnerability.io/vulnerability/CVE-2019-11822,,Relative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to upload arbitrary files via the uploadphoto parameter.,Synology,Photo Station,4.3,MEDIUM,0.0006300000241026282,false,,false,false,false,,,false,false,,2019-06-30T00:00:00.000Z,0 CVE-2019-11821,https://securityvulnerability.io/vulnerability/CVE-2019-11821,,SQL injection vulnerability in synophoto_csPhotoDB.php in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to execute arbitrary SQL command via the type parameter.,Synology,Photo Station,7.3,HIGH,0.0007399999885819852,false,,false,false,false,,,false,false,,2019-06-30T00:00:00.000Z,0 CVE-2018-13282,https://securityvulnerability.io/vulnerability/CVE-2018-13282,,Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attackers to hijack web sessions via the PHPSESSID parameter.,Synology,Photo Station,5.6,MEDIUM,0.0011899999808520079,false,,false,false,false,,,false,false,,2018-10-31T00:00:00.000Z,0 CVE-2018-8925,https://securityvulnerability.io/vulnerability/CVE-2018-8925,,"Cross-site request forgery (CSRF) vulnerability in admin/user.php in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote attackers to hijack the authentication of administrators via the (1) username, (2) password, (3) admin, (4) action, (5) uid, or (6) modify_admin parameter.",Synology,Photo Station,8.8,HIGH,0.0006399999838322401,false,,false,false,false,,,false,false,,2018-06-08T00:00:00.000Z,0 CVE-2018-8926,https://securityvulnerability.io/vulnerability/CVE-2018-8926,,Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote authenticated users to conduct privilege escalation attacks via the fullname parameter.,Synology,Photo Station,8.8,HIGH,0.0006300000241026282,false,,false,false,false,,,false,false,,2018-06-08T00:00:00.000Z,0 CVE-2017-16772,https://securityvulnerability.io/vulnerability/CVE-2017-16772,,Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote authenticated users to execute arbitrary codes via the prog_id parameter.,Synology,Photo Station,8.8,HIGH,0.0006399999838322401,false,,false,false,false,,,false,false,,2018-03-22T00:00:00.000Z,0 CVE-2017-16771,https://securityvulnerability.io/vulnerability/CVE-2017-16771,,Cross-site scripting (XSS) vulnerability in Log Viewer in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote attackers to inject arbitrary web script or HTML via the username parameter.,Synology,Photo Station,6.1,MEDIUM,0.0014199999859556556,false,,false,false,false,,,false,false,,2018-03-22T00:00:00.000Z,0 CVE-2017-16769,https://securityvulnerability.io/vulnerability/CVE-2017-16769,,Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from password-protected photographs via the map viewer mode.,Synology,Synology Photo Station,5.3,MEDIUM,0.001509999972768128,false,,false,false,false,,,false,false,,2018-02-23T22:29:00.000Z,0 CVE-2017-12072,https://securityvulnerability.io/vulnerability/CVE-2017-12072,,Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.8.0-3456 allows remote authenticated users to inject arbitrary web scripts or HTML via the id parameter.,Synology,Photo Station,5.4,MEDIUM,0.000539999979082495,false,,false,false,false,,,false,false,,2017-12-20T00:00:00.000Z,0 CVE-2017-12080,https://securityvulnerability.io/vulnerability/CVE-2017-12080,,An information exposure vulnerability in default HTTP configuration file in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain sensitive system information via .htaccess file.,Synology,Photo Station,5.3,MEDIUM,0.001509999972768128,false,,false,false,false,,,false,false,,2017-12-04T19:29:00.000Z,0 CVE-2017-12079,https://securityvulnerability.io/vulnerability/CVE-2017-12079,,Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain arbitrary files via prog_id field.,Synology,Photo Station,7.5,HIGH,0.0014600000577047467,false,,false,false,false,,,false,false,,2017-12-04T19:29:00.000Z,0 CVE-2017-12071,https://securityvulnerability.io/vulnerability/CVE-2017-12071,,Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to download arbitrary local files via the url parameter.,Synology,Synology Photo Station,6.5,MEDIUM,0.0005499999970197678,false,,false,false,false,,,false,false,,2017-09-08T00:00:00.000Z,0 CVE-2017-11162,https://securityvulnerability.io/vulnerability/CVE-2017-11162,,Directory traversal vulnerability in synphotoio in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to read arbitrary files via unspecified vectors.,Synology,Synology Photo Station,6.5,MEDIUM,0.0006099999882280827,false,,false,false,false,,,false,false,,2017-09-08T00:00:00.000Z,0 CVE-2017-11161,https://securityvulnerability.io/vulnerability/CVE-2017-11161,,Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to label.php; or (2) type parameter to synotheme.php.,Synology,Synology Photo Station,9.8,CRITICAL,0.0008200000156648457,false,,false,false,false,,,false,false,,2017-09-08T00:00:00.000Z,0 CVE-2017-9555,https://securityvulnerability.io/vulnerability/CVE-2017-9555,,Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.0-3414 allows remote attackers to inject arbitrary web script or HTML via the image parameter.,Synology,Synology Photo Station,5.4,MEDIUM,0.000539999979082495,false,,false,false,false,,,false,false,,2017-08-24T00:00:00.000Z,0 CVE-2017-11159,https://securityvulnerability.io/vulnerability/CVE-2017-11159,,"Multiple untrusted search path vulnerabilities in installer in Synology Photo Station Uploader before 1.4.2-084 on Windows allows local attackers to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current working directory.",Synology,Photo Station Uploader,7.8,HIGH,0.0006200000061653554,false,,false,false,false,,,false,false,,2017-08-23T00:00:00.000Z,0 CVE-2017-11154,https://securityvulnerability.io/vulnerability/CVE-2017-11154,,Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to create arbitrary PHP scripts via the type parameter.,Synology,Synology Photo Station,7.2,HIGH,0.3718400001525879,false,,false,false,false,,,false,false,,2017-08-08T15:29:00.000Z,0 CVE-2017-11153,https://securityvulnerability.io/vulnerability/CVE-2017-11153,,Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain administrator privileges via a crafted serialized payload.,Synology,Synology Photo Station,9.8,CRITICAL,0.7765200138092041,false,,false,false,false,,,false,false,,2017-08-08T15:29:00.000Z,0 CVE-2017-11151,https://securityvulnerability.io/vulnerability/CVE-2017-11151,,A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files without authentication via the logo_upload action.,Synology,Synology Photo Station,9.8,CRITICAL,0.5258200168609619,false,,false,false,false,,,false,false,,2017-08-08T15:29:00.000Z,0 CVE-2017-11152,https://securityvulnerability.io/vulnerability/CVE-2017-11152,,Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to write arbitrary files via the path parameter.,Synology,Synology Photo Station,7.5,HIGH,0.0032099999953061342,false,,false,false,false,,,false,false,,2017-08-08T15:29:00.000Z,0