Vulnerability index

Browse CVEs

280 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Diskstation Manager Unified Controller HIGH 8.1
CVE-2023-0142

Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-4…

Fix: 1.3.1-9346 / 7.1-42661+
Fix from $1,950 2023-06-13
Router Manager CRITICAL 9.8
CVE-2023-32956

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in CGI component in Synology Router Manager …

Fix: 1.2.5-8227-6 / 1.3.1-9346-3+
Fix from $2,300 2023-05-16
Router Manager HIGH 8.1
CVE-2023-32955

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DHCP Client Functionality in Synology Rou…

Fix: 1.2.5-8227-6 / 1.3.1-9346-3+
Fix from $1,950 2023-05-16
Router Manager CRITICAL 9.8
CVE-2023-0077

Integer overflow or wraparound vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote att…

Fix: 1.2.5-8227-6 / 1.3.1-9346-3+
Fix from $2,300 2023-01-05
Router Manager HIGH 7.5
CVE-2022-43932

Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in CGI component in Synology Router …

Fix: 1.2.5-8227-6 / 1.3.1-9346-3+
Fix from $1,950 2023-01-05
Vpn Plus Server CRITICAL 10.0
CVE-2022-43931EPSS 17%

Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server before 1.4.3-0534 and 1.4.4-0635 allows remote attacker…

Fix: 1.4.3-0534 / 1.4.4-0635+
Fix from $2,300 2023-01-03
Presto File Server HIGH 8.8
CVE-2022-43749

Improper privilege management vulnerability in summary report management in Synology Presto File Server before 2.1.2-1601 allows remote authenticated…

Fix: 2.1.2-1601+
Fix from $1,950 2022-10-26
Presto File Server HIGH 7.5
CVE-2022-43748

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file operation management in Synology Presto File Ser…

Fix: 2.1.2-1601+
Fix from $1,950 2022-10-26
Diskstation Manager CRITICAL 9.1
CVE-2022-27623

Missing authentication for critical function vulnerability in iSCSI management functionality in Synology DiskStation Manager (DSM) before 7.1-42661 a…

Fix: 7.1-42661+
Fix from $2,300 2022-10-25
Diskstation Manager HIGH 7.5
CVE-2022-3576

A vulnerability regarding out-of-bounds read is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote att…

Fix: 7.1.1-42962-2+
Fix from $1,950 2022-10-20
Diskstation Manager CRITICAL 9.8
CVE-2022-27625

A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the message processing functionality of…

Fix: 7.1.1-42962-2+
Fix from $2,300 2022-10-20
Diskstation Manager HIGH 8.1
CVE-2022-27626

A vulnerability regarding concurrent execution using shared resource with improper synchronization ('Race Condition') is found in the session process…

Fix: 7.1.1-42962-2+
Fix from $1,950 2022-10-20
Diskstation Manager CRITICAL 9.8
CVE-2022-27624

A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the packet decryption functionality of …

Fix: 7.1.1-42962-2+
Fix from $2,300 2022-10-20
Storage Analyzer MEDIUM 6.5
CVE-2022-27618

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Storage Analyzer before …

Fix: 2.0.1-0214 / 2.1.0-0390+
Fix from $1,600 2022-08-03
Note Station MEDIUM 5.9
CVE-2022-27619

Cleartext transmission of sensitive information vulnerability in authentication management in Synology Note Station Client before 2.2.2-609 allows ma…

Fix: 2.2.2-609+
Fix from $1,600 2022-08-03
Diskstation Manager HIGH 7.2
CVE-2022-27616

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in webapi component in Synology DiskStation …

Fix: 6.2.4-25556-5 / 7.0.1-42218-3+
Fix from $1,950 2022-08-03
Audio Station HIGH 8.1
CVE-2022-27611

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Audio Station before 6.5…

Fix: 6.5.4-3367+
Fix from $1,950 2022-07-28
Media Server HIGH 7.5
CVE-2022-27614

Exposure of sensitive information to an unauthorized actor vulnerability in web server in Synology Media Server before 1.8.1-2876 allows remote attac…

Fix: 1.4-2665 / 1.8.1-2876+
Fix from $1,950 2022-07-28
Media Server CRITICAL 9.8
CVE-2022-22683

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allo…

Fix: 1.4-2665 / 1.8.1-2876+
Fix from $2,300 2022-07-28
Audio Station CRITICAL 9.8
CVE-2022-27612

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Audio Station before 6.5.4-3367 all…

Fix: 6.5.4-3367+
Fix from $2,300 2022-07-28
Diskstation Manager HIGH 8.8
CVE-2022-22684

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in task management component in Synology Dis…

Fix: 6.2.4-25553+
Fix from $1,950 2022-07-28
Carddav Server HIGH 8.8
CVE-2022-27613

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in webapi component in Synology CardDAV Server bef…

Fix: 6.0.10-0153+
Fix from $1,950 2022-07-28
Webdav Server HIGH 8.1
CVE-2022-22685

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology WebDAV Server before 2.4…

Fix: 2.4.0-0062+
Fix from $1,950 2022-07-28
Dns Server HIGH 8.1
CVE-2022-27615

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology DNS Server before 2.2.2-502…

Fix: 2.2.2-5027+
Fix from $1,950 2022-07-28
Diskstation Manager HIGH 8.1
CVE-2022-27610

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM…

Fix: 6.2.3-25423+
Fix from $1,950 2022-07-27
Calendar HIGH 8.0
CVE-2022-22686

Cross-Site Request Forgery (CSRF) vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to hijac…

Fix: 2.3.4-0631+
Fix from $1,950 2022-07-26
Calendar MEDIUM 5.4
CVE-2022-22682

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Event Management in Synology Calendar before 2.…

Fix: 2.4.5-10930+
Fix from $1,600 2022-07-12
Photo Station HIGH 7.5
CVE-2022-22681

Session fixation vulnerability in access control management in Synology Photo Station before 6.8.16-3506 allows remote attackers to bypass security c…

Fix: 6.8.16-3506+
Fix from $1,950 2022-07-06
Diskstation Manager CRITICAL 9.8
CVE-2022-22687

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager …

Fix: 3.1-23033 / 6.2.3-25426-3+
Fix from $2,300 2022-03-25
Diskstation Manager HIGH 8.8
CVE-2022-22688

Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology DiskStati…

Fix: 6.2.4-25556-2 / 7.0.1-42214+
Fix from $1,950 2022-03-25