Vulnerabilities > Synology > Video Station > 2.1.2.1236

DATE CVE VULNERABILITY TITLE RISK
2021-06-01 CVE-2021-33181 Server-Side Request Forgery (SSRF) vulnerability in Synology Video Station
Server-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station before 2.4.10-1632 allows remote authenticated users to send arbitrary request to intranet resources via unspecified vectors.
network
low complexity
synology CWE-918
6.5
2017-08-11 CVE-2017-9556 Cross-site Scripting vulnerability in Synology Video Station
Cross-site scripting (XSS) vulnerability in Video Metadata Editor in Synology Video Station before 2.3.0-1435 allows remote authenticated attackers to inject arbitrary web script or HTML via the title parameter.
network
synology CWE-79
3.5