VYPR

Vendor CVEs

Synology

All CVEs

377 total · sorted by risk
  • CVE-2026-13635MedSep 18, 2026
    risk 0.34cvss 5.3epss 0.00

    An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to obtain non-sensitive information.

  • CVE-2023-52950MedSep 26, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing encryption of sensitive data vulnerability in login component in Synology Active Backup for Business Agent before 2.7.0-3221 allows adjacent man-in-the-middle attackers to obtain user credential via unspecified vectors.

  • CVE-2023-52948MedSep 26, 2024
    risk 0.33cvss 5.0epss 0.00

    Missing encryption of sensitive data vulnerability in settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecified vectors.

  • CVE-2022-27617MedAug 3, 2022
    risk 0.33cvss 5.0epss 0.01

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to download arbitrary files via unspecified vectors.

  • CVE-2021-34811MedJun 18, 2021
    risk 0.33cvss 5.0epss 0.01

    Server-Side Request Forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to access intranet resources via unspecified vectors.

  • CVE-2021-33182MedJun 1, 2021
    risk 0.33cvss 5.0epss 0.01

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in PDF Viewer component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows remote authenticated users to read limited files via unspecified vectors.

  • CVE-2024-47271MedMay 27, 2026
    risk 0.32cvss 4.9epss 0.00

    Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.

  • CVE-2024-47269MedMay 27, 2026
    risk 0.32cvss 4.9epss 0.00

    Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.

  • CVE-2024-47268MedMay 27, 2026
    risk 0.32cvss 4.9epss 0.00

    Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.

  • CVE-2024-47264MedFeb 13, 2025
    risk 0.32cvss 4.9epss 0.01

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users with administrator privileges to…

  • CVE-2024-39352MedJun 28, 2024
    risk 0.32cvss 4.9epss 0.01

    A vulnerability regarding incorrect authorization is found in the firmware upgrade functionality. This allows remote authenticated users with administrator privileges to bypass firmware integrity check via unspecified vectors. The following models with Synology Camera Firmware…

  • CVE-2023-41739MedAug 31, 2023
    risk 0.32cvss 4.9epss 0.01

    Uncontrolled resource consumption vulnerability in File Functionality in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote authenticated users to conduct denial-of-service attacks via unspecified vectors.

  • CVE-2019-14847MedNov 6, 2019
    risk 0.32cvss 4.9epss 0.02

    A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10.10. An attacker can crash AD DC LDAP server via dirsync resulting in denial of service. Privilege escalation is not possible with this issue.

  • CVE-2017-12077MedAug 28, 2017
    risk 0.32cvss 4.9epss 0.01

    Uncontrolled Resource Consumption vulnerability in SYNO.Core.PortForwarding.Rules in Synology Router Manager (SRM) before 1.1.4-6509 allows remote authenticated attacker to exhaust the memory resources of the machine, causing a denial of service attack.

  • CVE-2017-12076MedAug 28, 2017
    risk 0.32cvss 4.9epss 0.01

    Uncontrolled Resource Consumption vulnerability in SYNO.Core.PortForwarding.Rules in Synology DiskStation (DSM) before 6.1.1-15088 allows remote authenticated attacker to exhaust the memory resources of the machine, causing a denial of service attack.

  • CVE-2026-13623MedSep 18, 2026
    risk 0.31cvss 4.8epss 0.00

    An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator…

  • CVE-2021-43927MedFeb 7, 2022
    risk 0.31cvss 4.7epss 0.01

    Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Security Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inject SQL commands via unspecified vectors.

  • CVE-2021-43926MedFeb 7, 2022
    risk 0.31cvss 4.7epss 0.01

    Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inject SQL commands via unspecified vectors.

  • CVE-2021-43925MedFeb 7, 2022
    risk 0.31cvss 4.7epss 0.01

    Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inject SQL commands via unspecified vectors.

  • CVE-2017-16768MedDec 27, 2017
    risk 0.31cvss 4.8epss 0.01

    Cross-site scripting (XSS) vulnerability in User Policy editor in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary HTML via the name parameter.

  • CVE-2017-15890MedDec 15, 2017
    risk 0.31cvss 4.8epss 0.01

    Cross-site scripting (XSS) vulnerability in Disclaimer in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary web script or HTML via the NAME parameter.

  • CVE-2022-49041MedSep 26, 2024
    risk 0.29cvss 4.4epss 0.00

    Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in backup task management functionality in Synology Drive Client before 3.4.0-15721 allows local users with administrator privileges to crash the client via unspecified vectors.

  • CVE-2022-49040MedSep 26, 2024
    risk 0.29cvss 4.4epss 0.00

    Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in connection management functionality in Synology Drive Client before 3.4.0-15721 allows local users with administrator privileges to crash the client via unspecified vectors.

  • CVE-2026-40537MedSep 18, 2026
    risk 0.28cvss 4.3epss 0.00

    A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.

  • CVE-2026-40536MedSep 18, 2026
    risk 0.28cvss 4.3epss 0.00

    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.

  • CVE-2026-40531MedSep 18, 2026
    risk 0.28cvss 4.3epss 0.00

    An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to conduct limited denial-of-service attacks.

  • CVE-2026-9491MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote authenticated users to obtain non-sensitive information.

  • CVE-2024-47273MedJun 3, 2026
    risk 0.28cvss 4.3epss 0.00

    An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors.

  • CVE-2025-29845MedDec 4, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.

  • CVE-2025-29844MedDec 4, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.

  • CVE-2024-5401MedDec 4, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before 7.1.1-42962-8 and 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote authenticated users to…

  • CVE-2024-10445MedMar 19, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to write…

  • CVE-2023-52944MedDec 4, 2024
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization vulnerability in ActionRule webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to perform limited actions on the set action rules function via unspecified vectors.

  • CVE-2023-52943MedDec 4, 2024
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization vulnerability in Alert.Setting webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to to perform limited actions on the alerting function via unspecified vectors.

  • CVE-2024-29240MedMar 28, 2024
    risk 0.28cvss 4.3epss 0.01

    Missing authorization vulnerability in LayoutSave webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to conduct limited denial-of-service attacks via unspecified vectors.

  • CVE-2022-43749MedOct 26, 2022
    risk 0.28cvss 4.3epss 0.01

    Improper privilege management vulnerability in summary report management in Synology Presto File Server before 2.1.2-1601 allows remote authenticated users to bypass security constraint via unspecified vectors.

  • CVE-2019-11822MedJun 30, 2019
    risk 0.28cvss 4.3epss 0.01

    Relative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to upload arbitrary files via the uploadphoto parameter.

  • CVE-2018-13299MedApr 1, 2019
    risk 0.28cvss 4.3epss 0.01

    Relative path traversal vulnerability in Attachment Uploader in Synology Calendar before 2.2.2-0532 allows remote authenticated users to upload arbitrary files via the filename parameter.

  • CVE-2018-13295MedApr 1, 2019
    risk 0.28cvss 4.3epss 0.01

    Information exposure vulnerability in SYNO.Personal.Application.Info in Synology Application Service before 1.5.4-0320 allows remote authenticated users to obtain sensitive system information via the version parameter.

  • CVE-2018-13294MedApr 1, 2019
    risk 0.28cvss 4.3epss 0.01

    Information exposure vulnerability in SYNO.Personal.Profile in Synology Application Service before 1.5.4-0320 allows remote authenticated users to obtain sensitive system information via the uid parameter.

  • CVE-2018-13292MedApr 1, 2019
    risk 0.28cvss 4.3epss 0.01

    Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to obtain sensitive information via the world readable configuration.

  • CVE-2018-13291MedApr 1, 2019
    risk 0.28cvss 4.3epss 0.01

    Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology DiskStation Manager (DSM) before 6.2.1-23824 allows remote authenticated users to obtain sensitive information via the world readable configuration.

  • CVE-2018-13290MedApr 1, 2019
    risk 0.28cvss 4.3epss 0.01

    Information exposure vulnerability in SYNO.Core.ACL in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to determine the existence of files or obtain sensitive information of files via the file_path parameter.

  • CVE-2018-13281MedOct 31, 2018
    risk 0.28cvss 4.3epss 0.01

    Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remote authenticated users to determine the existence and obtain the metadata of arbitrary files via the file_path parameter.

  • CVE-2024-47263MedJun 3, 2026
    risk 0.27cvss 4.1epss 0.00

    An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing…

  • CVE-2022-27622MedOct 25, 2022
    risk 0.27cvss 4.1epss 0.01

    Server-Side Request Forgery (SSRF) vulnerability in Package Center functionality in Synology DiskStation Manager (DSM) before 7.1-42661 allows remote authenticated users to access intranet resources via unspecified vectors.

  • CVE-2018-13298MedApr 1, 2019
    risk 0.27cvss 4.2epss 0.01

    Channel accessible by non-endpoint vulnerability in privacy page in Synology Android Moments before 1.2.3-199 allows man-in-the-middle attackers to execute arbitrary code via unspecified vectors.

  • CVE-2023-52947MedSep 26, 2024
    risk 0.26cvss 4.0epss 0.00

    Missing authentication for critical function vulnerability in logout functionality in Synology Active Backup for Business Agent before 2.6.3-3101 allows local users to logout the client via unspecified vectors. The backup functionality will continue to operate and will not be…

  • CVE-2026-40538LowSep 18, 2026
    risk 0.24cvss 3.7epss 0.00

    An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to read limited files via brute-force attacks.

  • CVE-2019-9495LowApr 17, 2019
    risk 0.24cvss 3.7epss 0.03

    The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary…

Page 7 of 8