VYPR
Vendor

Synology

Products
103
CVEs
377
Across products
492
Status
Private

Products

103
View all 103 products →

Recent CVEs

377
View all 377 CVEs →
  • CVE-2018-1160CriDec 20, 2018
    risk 0.74cvss 9.8epss 0.87

    Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.

  • CVE-2017-14491CriOct 4, 2017
    risk 0.73cvss 9.8epss 0.85

    Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.

  • CVE-2017-11153CriAug 8, 2017
    risk 0.68cvss 9.8epss 0.12

    Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain administrator privileges via a crafted serialized payload.

  • CVE-2017-11151CriAug 8, 2017
    risk 0.68cvss 9.8epss 0.16

    A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files without authentication via the logo_upload action.

  • CVE-2021-3156HigKEVJan 26, 2021
    risk 0.67cvss 7.8epss 1.00

    Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

  • CVE-2016-10329CriMay 12, 2017
    risk 0.67cvss 9.8epss 0.41

    Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell metacharacters in the crafted 'X-Forwarded-For' header.

  • CVE-2024-10443CriNov 15, 2024
    risk 0.66cvss 9.8epss 0.28

    Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute…

  • CVE-2022-43931CriJan 3, 2023
    risk 0.66cvss 10.0epss 0.17

    Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server before 1.4.3-0534 and 1.4.4-0635 allows remote attackers to execute arbitrary commands via unspecified vectors.

  • CVE-2017-15889HigDec 4, 2017
    risk 0.66cvss 8.8epss 0.74

    Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field.

  • CVE-2024-10442CriMar 19, 2025
    risk 0.65cvss 10.0epss 0.01

    Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code, potentially leading to a…

  • CVE-2022-27626CriOct 20, 2022
    risk 0.65cvss 10.0epss 0.01

    A vulnerability regarding concurrent execution using shared resource with improper synchronization ('Race Condition') is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified…

  • CVE-2022-27625CriOct 20, 2022
    risk 0.65cvss 10.0epss 0.02

    A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the message processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following…

  • CVE-2022-27624CriOct 20, 2022
    risk 0.65cvss 10.0epss 0.02

    A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the packet decryption functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following…

  • CVE-2022-22683CriJul 28, 2022
    risk 0.65cvss 10.0epss 0.02

    Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allows remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2021-34809CriJun 18, 2021
    risk 0.65cvss 9.9epss 0.02

    Improper neutralization of special elements used in a command ('Command Injection') vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to execute arbitrary code via unspecified vectors.

  • CVE-2026-13684CriSep 18, 2026
    risk 0.64cvss 9.8epss 0.01

    An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.

  • CVE-2026-13639CriSep 18, 2026
    risk 0.64cvss 9.8epss 0.01

    An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.

  • CVE-2025-12686CriMay 27, 2026
    risk 0.64cvss 9.8epss 0.03

    Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2024-11131CriMar 19, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability regarding out-of-bounds read is found in the video interface. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camera Firmware versions before 1.2.0-0525 may be affected: BC500, CC400W and TC500.

  • CVE-2024-10441CriMar 19, 2025
    risk 0.64cvss 9.8epss 0.01

    Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allows remote attackers to execute arbitrary code via…

VYPR — Vulnerability Intelligence