Vulnerability index

Browse CVEs

280 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Router Manager HIGH 7.5
CVE-2024-39348

Download of code without integrity check vulnerability in AirPrint functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346…

Fix: 1.2.5-8227 / 1.3.1-9346+
Fix from $1,950 2024-06-28
Tc500 Firmware HIGH 7.5
CVE-2024-39350

A vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows man-in-the-middle attackers to obtain pri…

Fix: 1.0.7-0298+
Fix from $1,950 2024-06-28
Router Manager MEDIUM 5.9
CVE-2024-39347

Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows m…

Fix: 1.2.5-8227 / 1.3.1-9346+
Fix from $1,600 2024-06-28
Bc500 Firmware CRITICAL 9.8
CVE-2024-39349

A vulnerability regarding buffer copy without checking size of input ('Classic Buffer Overflow') is found in the libjansson component and it does not…

Fix: 1.0.7-0298+
Fix from $2,300 2024-06-28
Bc500 Firmware HIGH 7.2
CVE-2024-39351

A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the NTP configuratio…

Fix: 1.0.7-0298+
Fix from $1,950 2024-06-28
Bc500 Firmware MEDIUM 5.3
CVE-2023-47803

A vulnerability regarding improper limitation of a pathname to a restricted directory ('Path Traversal') is found in the Language Settings functional…

Fix: 1.0.7-0298+
Fix from $1,600 2024-06-28
Bc500 Firmware HIGH 7.2
CVE-2023-47802

A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the IP block functio…

Fix: 1.0.7-0298+
Fix from $1,950 2024-06-28
Bc500 Firmware MEDIUM 6.5
CVE-2024-5463

A vulnerability regarding buffer copy without checking the size of input ('Classic Buffer Overflow') has been found in the login component. This allo…

Fix: 1.1.1-0383+
Fix from $1,600 2024-06-04
Surveillance Station CRITICAL 9.9
CVE-2024-29241

Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authe…

Fix: 9.2.0-9289 / 9.2.0-11289+
Fix from $2,300 2024-03-28
Surveillance Station MEDIUM 5.4
CVE-2024-29239

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Recording.CountByCategory webapi component in S…

Fix: 9.2.0-9289 / 9.2.0-11289+
Fix from $1,600 2024-03-28
Surveillance Station MEDIUM 5.4
CVE-2024-29237

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in ActionRule.Delete webapi component in Synology …

Fix: 9.2.0-9289 / 9.2.0-11289+
Fix from $1,600 2024-03-28
Surveillance Station MEDIUM 5.4
CVE-2024-29238

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log.CountByCategory webapi component in Synolog…

Fix: 9.2.0-9289 / 9.2.0-11289+
Fix from $1,600 2024-03-28
Surveillance Station MEDIUM 5.4
CVE-2024-29236

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in AudioPattern.Delete webapi component in Synolog…

Fix: 9.2.0-9289 / 9.2.0-11289+
Fix from $1,600 2024-03-28
Surveillance Station MEDIUM 5.4
CVE-2024-29235

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in IOModule.EnumLog webapi component in Synology S…

Fix: 9.2.0-9289 / 9.2.0-11289+
Fix from $1,600 2024-03-28
Surveillance Station MEDIUM 5.4
CVE-2024-29233

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Emap.Delete webapi component in Synology Survei…

Fix: 9.2.0-9289 / 9.2.0-11289+
Fix from $1,600 2024-03-28
Surveillance Station MEDIUM 5.4
CVE-2024-29234

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi component in Synology Surveil…

Fix: 9.2.0-9289 / 9.2.0-11289+
Fix from $1,600 2024-03-28
Surveillance Station MEDIUM 5.4
CVE-2024-29232

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Alert.Enum webapi component in Synology Surveil…

Fix: 9.2.0-9289 / 9.2.0-11289+
Fix from $1,600 2024-03-28
Surveillance Station MEDIUM 5.4
CVE-2024-29231

Improper validation of array index vulnerability in UserPrivilege.Enum webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-…

Fix: 9.2.0-9289 / 9.2.0-11289+
Fix from $1,600 2024-03-28
Surveillance Station MEDIUM 5.4
CVE-2024-29230

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in SnapShot.CountByCategory webapi component in Sy…

Fix: 9.2.0-9289 / 9.2.0-11289+
Fix from $1,600 2024-03-28
Surveillance Station HIGH 7.7
CVE-2024-29229

Missing authorization vulnerability in GetLiveViewPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows rem…

Fix: 9.2.0-9289 / 9.2.0-11289+
Fix from $1,950 2024-03-28
Surveillance Station HIGH 7.7
CVE-2024-29228

Missing authorization vulnerability in GetStmUrlPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remot…

Fix: 9.2.0-9289 / 9.2.0-11289+
Fix from $1,950 2024-03-28
Surveillance Station MEDIUM 5.4
CVE-2024-29227

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Layout.LayoutSave webapi component in Synology …

Fix: 9.2.0-9289 / 9.2.0-11289+
Fix from $1,600 2024-03-28
Diskstation Manager MEDIUM 5.4
CVE-2024-0854

URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manager (DSM) before 6.2.4-25556-8…

Fix: 7.2.1-69057-2+
Fix from $1,600 2024-01-24
Ssl Vpn Client MEDIUM 5.5
CVE-2023-5748

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology SSL VPN Client before 1.4.7-0687 al…

Fix: 1.4.7-0687+
Fix from $1,600 2023-11-07
Bc500 Firmware CRITICAL 9.8
CVE-2023-5746

A vulnerability regarding use of externally-controlled format string is found in the cgi component. This allows remote attackers to execute arbitrary…

Fix: 1.0.5-0185+
Fix from $2,300 2023-10-25
Router Manager HIGH 8.8
CVE-2023-41738

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Directory Domain Functionality in Synolog…

Fix: 1.3.1-9346-6+
Fix from $1,950 2023-08-31
Router Manager HIGH 7.5
CVE-2023-41741

Exposure of sensitive information to an unauthorized actor vulnerability in cgi component in Synology Router Manager (SRM) before 1.3.1-9346-6 allows…

Fix: 1.3.1-9346-6+
Fix from $1,950 2023-08-31
Router Manager MEDIUM 6.5
CVE-2023-41739

Uncontrolled resource consumption vulnerability in File Functionality in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote authenticate…

Fix: 1.3.1-9346-6+
Fix from $1,600 2023-08-31
Router Manager MEDIUM 5.3
CVE-2023-41740

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology Router Manager (SRM) before…

Fix: 1.3.1-9346-6+
Fix from $1,600 2023-08-31
Diskstation Manager Unified Controller HIGH 7.5
CVE-2023-2729

Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7.2-64561 allows remo…

Fix: 1.3.1-9346 / 7.2-64561+
Fix from $1,950 2023-06-13