VYPR

Diskstation Manager

by Synology

CVEs (116)

  • CVE-2026-40539HigSep 18, 2026
    risk 0.46cvss 7.1epss 0.00

    An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows man-in-the-middle attackers to read or write arbitrary files and conduct denial-of-service attacks.

  • CVE-2019-14907MedJan 21, 2020
    risk 0.43cvss 6.5epss 0.03

    All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during…

  • CVE-2017-9554MedJul 24, 2017
    risk 0.43cvss 5.3epss 0.78

    An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspecified vectors.

  • CVE-2026-4036MedSep 18, 2026
    risk 0.42cvss 6.5epss 0.00

    An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain arbitrary sharing files.

  • CVE-2026-40535MedSep 18, 2026
    risk 0.42cvss 6.5epss 0.00

    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to write limited files and conduct limited…

  • CVE-2026-40532MedSep 18, 2026
    risk 0.42cvss 6.5epss 0.00

    A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain sensitive information.

  • CVE-2023-0142MedJun 13, 2023
    risk 0.42cvss 6.5epss 0.01

    Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via…

  • CVE-2022-27610MedJul 27, 2022
    risk 0.42cvss 6.5epss 0.02

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25423 allows remote authenticated users to delete arbitrary files via unspecified vectors.

  • CVE-2022-22679MedFeb 7, 2022
    risk 0.42cvss 6.5epss 0.01

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in support service management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote authenticated users to write arbitrary files via unspecified vectors.

  • CVE-2021-43929MedFeb 7, 2022
    risk 0.42cvss 6.5epss 0.01

    Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in work flow management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote authenticated users to inject arbitrary web script or HTML via…

  • CVE-2020-27656MedOct 29, 2020
    risk 0.42cvss 6.5epss 0.01

    Cleartext transmission of sensitive information vulnerability in DDNS in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via unspecified vectors.

  • CVE-2019-19344MedJan 21, 2020
    risk 0.42cvss 6.5epss 0.03

    There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all samba 4.10.x versions before 4.10.12 and all samba 4.11.x versions before 4.11.5, essentially due to a call to realloc() while other local variables still point at the original buffer.

  • CVE-2018-13286MedApr 1, 2019
    risk 0.42cvss 6.5epss 0.01

    Incorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to obtain sensitive information via the world readable configuration.

  • CVE-2017-16774MedApr 1, 2019
    risk 0.42cvss 6.5epss 0.01

    Cross-site scripting (XSS) vulnerability in SYNO.Core.PersonalNotification.Event in Synology DiskStation Manager (DSM) before 6.1.4-15217-3 allows remote authenticated users to inject arbitrary web script or HTML via the package parameter.

  • CVE-2018-8917MedDec 24, 2018
    risk 0.42cvss 6.5epss 0.01

    Cross-site scripting (XSS) vulnerability in info.cgi in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to inject arbitrary web script or HTML via the host parameter.

  • CVE-2017-16766MedDec 22, 2017
    risk 0.42cvss 6.5epss 0.01

    An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows local users to inject arbitrary web script or HTML via the -fn option.

  • CVE-2017-15894MedDec 8, 2017
    risk 0.42cvss 6.5epss 0.02

    Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology DiskStation Manager (DSM) 6.0.x before 6.0.3-8754-3 and before 5.2-5967-6 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.

  • CVE-2018-8916MedJun 8, 2018
    risk 0.41cvss 6.3epss 0.01

    Unverified password change vulnerability in Change Password in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to reset password without verification.

  • CVE-2019-3870MedApr 9, 2019
    risk 0.40cvss 6.1epss 0.01

    A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only…

  • CVE-2023-2729MedJun 13, 2023
    risk 0.38cvss 5.9epss 0.01

    Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7.2-64561 allows remote attackers to obtain user credential via unspecified vectors.

Page 4 of 6