Vulnerability index

Browse CVEs

280 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Router Manager MEDIUM 5.9
CVE-2024-53287

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functionality in Synology Router Ma…

Fix: 1.3.1-9346+
Fix from $1,600 2025-07-23
Active Backup For Microsoft 365 MEDIUM 6.5
CVE-2025-4679

A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive information via unspecified vec…

Mitigation only
Fix from $1,600 2025-05-16
Diskstation Manager HIGH 7.5
CVE-2025-1021

Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows re…

Fix: 7.1.1-42962-8 / 7.2.1-69057-7+
Fix from $1,950 2025-04-23
Drive Server HIGH 7.5
CVE-2024-50630EPSS 23%

Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26…

Fix: 3.0.4-12699 / 3.2.1-23280+
Fix from $1,950 2025-03-19
Drive Server HIGH 7.5
CVE-2024-50631EPSS 25%

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in the system syncing daemon in Synology Drive Ser…

Fix: 3.0.4-12699 / 3.2.1-23280+
Fix from $1,950 2025-03-19
Beestation Os MEDIUM 5.3
CVE-2024-50629EPSS 28%

Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStati…

Fix: 7.1.1-42962-7 / 7.2.1-69057-6+
Fix from $1,600 2025-03-19
Tc500 Firmware CRITICAL 9.8
CVE-2024-11131

A vulnerability regarding out-of-bounds read is found in the video interface. This allows remote attackers to execute arbitrary code via unspecified …

Fix: 1.2.0-0525+
Fix from $2,300 2025-03-19
Unified Controller CRITICAL 10.0
CVE-2024-10442

Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423 and Synolo…

Fix: 1.2.2-0353 / 1.3.0-0423+
Fix from $2,300 2025-03-19
Diskstation Manager HIGH 7.5
CVE-2024-10444

Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2…

Fix: 7.1.1-42962-8 / 7.2.1-69057-7+
Fix from $1,950 2025-03-19
Beestation Os MEDIUM 5.3
CVE-2024-10445

Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation M…

Fix: 6.2.4-25556-8 / 7.2.1-69057-6+
Fix from $1,600 2025-03-19
Beestation Os CRITICAL 9.8
CVE-2024-10441

Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskS…

Fix: 7.2.1-69057-6 / 7.2.2-72806-1+
Fix from $2,300 2025-03-19
Active Backup For Business Agent MEDIUM 6.5
CVE-2024-47265

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount functionality in Synology Acti…

Fix: 2.7.1-3234 / 2.7.1-13234+
Fix from $1,600 2025-02-13
Active Backup For Business Agent MEDIUM 6.5
CVE-2024-47264

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functionality in Synology Active Backup…

Fix: 2.7.1-3234 / 2.7.1-13234+
Fix from $1,600 2025-02-13
Media Server HIGH 7.5
CVE-2024-4464

Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-2680, 2.0.5-3152 and 2.2.0-33…

Fix: 1.4-2680 / 2.0.5-3152+
Fix from $1,950 2024-12-18
Router Manager MEDIUM 5.9
CVE-2024-53283

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Router Port Forward functionality in Synology R…

Fix: 1.3.1-9346+
Fix from $1,600 2024-12-09
Router Manager MEDIUM 5.9
CVE-2024-53284

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect Setting functionality in Synology …

Fix: 1.3.1-9346+
Fix from $1,600 2024-12-09
Router Manager MEDIUM 5.9
CVE-2024-53285

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in DDNS Record functionality in Synology Router Ma…

Fix: 1.3.1-9346+
Fix from $1,600 2024-12-09
Router Manager MEDIUM 5.9
CVE-2024-53279

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in file station functionality in Synology Router M…

Fix: 1.3.1-9346+
Fix from $1,600 2024-12-09
Router Manager MEDIUM 5.9
CVE-2024-53280

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in network center policy route functionality in Sy…

Fix: 1.3.1-9346+
Fix from $1,600 2024-12-09
Router Manager MEDIUM 5.9
CVE-2024-53281

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Network WOL functionality in Synology Router Ma…

Fix: 1.3.1-9346+
Fix from $1,600 2024-12-09
Router Manager MEDIUM 5.9
CVE-2024-53282

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect MAC Filter functionality in Synolo…

Fix: 1.3.1-9346+
Fix from $1,600 2024-12-09
Router Manager HIGH 8.1
CVE-2024-11398

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality in Synology Router Manager (S…

Fix: 1.3.1-9346+
Fix from $1,950 2024-12-04
Photos CRITICAL 9.8
CVE-2024-10443EPSS 28%

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePho…

Fix: 1.0.2-10026 / 1.1.0-10053+
Fix from $2,300 2024-11-15
Active Backup For Business Agent MEDIUM 5.5
CVE-2023-52949

Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for Business Agent before 2.7.0-…

Fix: 2.7.0-3221+
Fix from $1,600 2024-09-26
Active Backup For Business Agent MEDIUM 5.3
CVE-2023-52950

Missing encryption of sensitive data vulnerability in login component in Synology Active Backup for Business Agent before 2.7.0-3221 allows adjacent …

Fix: 2.7.0-3221+
Fix from $1,600 2024-09-26
Active Backup For Business Agent MEDIUM 5.0
CVE-2023-52948

Missing encryption of sensitive data vulnerability in settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows lo…

Fix: 2.7.0-3221+
Fix from $1,600 2024-09-26
Drive Client HIGH 8.2
CVE-2023-52946

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in vss service component in Synology Drive Client before 3.5.0-1…

Fix: 3.5.0-16084+
Fix from $1,950 2024-09-26
Drive Client MEDIUM 6.7
CVE-2022-49039

Out-of-bounds write vulnerability in backup task management functionality in Synology Drive Client before 3.4.0-15721 allows local users with adminis…

Fix: 3.4.0-15721+
Fix from $1,600 2024-09-26
Drive Client HIGH 7.8
CVE-2022-49038

Inclusion of functionality from untrusted control sphere vulnerability in OpenSSL DLL component in Synology Drive Client before 3.3.0-15082 allows lo…

Fix: 3.3.0-15082+
Fix from $1,950 2024-09-26
Drive Client MEDIUM 6.5
CVE-2022-49037

Insertion of sensitive information into log file vulnerability in proxy settings component in Synology Drive Client before 3.3.0-15082 allows remote …

Fix: 3.3.0-15082+
Fix from $1,600 2024-09-26