Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2026-67248
A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because user-controlled input is not …
Data Master
5.1.4.rjv2+
MEDIUM 6.5
CVE-2026-67247
A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlled disk serial input is not su…
Data Master
5.1.4.rjv2+
HIGH 8.1
CVE-2026-67245
A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled certificate name input is no…
Data Master
5.1.4.rjv2+
MEDIUM 6.5
CVE-2026-67246
A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-controlled wallpaper path input is …
Data Master
5.1.4.rjv2+
HIGH 7.2
CVE-2026-67244
A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user-controlled notification conf…
Data Master
5.1.4.rjv2+
HIGH 8.1
CVE-2026-18186
A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-controlled backup configuration da…
Data Master
5.1.4.rjv2+
HIGH 8.1
CVE-2026-18187
A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-controlled task input may be include…
Data Master
5.1.4.rjv2+
HIGH 8.1
CVE-2026-18188
A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled rsync backup configuration o…
Data Master
5.1.4.rjv2+
CRITICAL 9.9
CVE-2026-6643
A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounded sscanf() and passing u…
Data Master
4.3.3.RR42 / 5.1.2.reo1+
CRITICAL 9.1
CVE-2026-6644
A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the r…
Data Master
4.3.3.RR42 / 5.1.2.reo1+
HIGH 8.1
CVE-2026-3179
The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MI…
Data Master
5.1.2.reo1+
MEDIUM 6.5
CVE-2026-3100
The FTP Backup on the ADM will not properly strictly enforce TLS certificate verification while connecting to an FTP server using FTPES/FTPS. An impr…
Data Master
5.1.2.reo1+
CRITICAL 9.8
CVE-2026-24936
When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI progr…
Data Master
5.1.2.re51+
MEDIUM 5.9
CVE-2026-24932
The DDNS update function in ADM fails to properly validate the hostname of the DDNS server's TLS/SSL certificate. Although the connection uses HTTPS,…
Data Master
5.1.2.re51+
MEDIUM 5.9
CVE-2026-24933
The API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An improper certificates validat…
Data Master
5.1.2.re51+
MEDIUM 5.6
CVE-2026-24935
A third-party NAT traversal module fails to validate SSL/TLS certificates when connecting to the signaling server. While subsequent access to device …
Data Master
5.1.2.re51+
MEDIUM 5.9
CVE-2025-13052
When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacke…
Data Master
4.3.3.ROF1 / 5.1.1.RCI1+
MEDIUM 5.5
CVE-2023-4475
An Arbitrary File Movement vulnerability was found in ASUSTOR Data Master (ADM) allows an attacker to exploit the file renaming feature to move files…
Data Master
4.2.2.ri61+
MEDIUM 5.5
CVE-2023-3699
An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users to modify the storage device…
Data Master
4.2.3.rk91+
HIGH 8.8
CVE-2023-2910
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Ma…
Data Master
4.2.3.rk91+
HIGH 8.8
CVE-2023-3697
Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and …
Data Master
4.2.3.rk91+
HIGH 8.1
CVE-2023-3698
Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and …
Data Master
4.2.3.rk91+
CRITICAL 10.0
CVE-2023-2909
EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Aff…
Adm
after 4.2.1.rge2
HIGH 7.5
CVE-2023-2749
Download Center fails to properly validate the file path submitted by a user, An attacker can exploit this vulnerability to gain unauthorized access …
Download Center
1.1.5.r1298+
MEDIUM 6.1
CVE-2023-2509
A Cross-Site Scripting(XSS) vulnerability was found on ADM, LooksGood and SoundsGood Apps. An attacker can exploit this vulnerability to inject malic…
Adm
Mitigation only
CRITICAL 9.8
CVE-2023-30770
A stack-based buffer overflow vulnerability was found in the ASUSTOR Data Master (ADM) due to the lack of data size validation. An attacker can explo…
Adm
4.2.1.rge2+
HIGH 8.8
CVE-2022-37398
A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack of data size validation. An attacker can exploit t…
Adm
after 4.1.0.rjd1
HIGH 8.1
CVE-2019-11689
An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl fail to properly valida…
Exfat Driver
No fix yet
HIGH 7.4
CVE-2019-11688
An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl accept any certificate …
Exfat Driver
No fix yet
CRITICAL 9.8
CVE-2018-12313
OS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "rocommunity…
Data Master
No fix yet