Vulnerability index

Browse CVEs

280 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Diskstation Manager CRITICAL 9.8
CVE-2021-43926

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskSt…

Fix: 6.2.4-25556-3 / 7.0.1-42218-2+
Fix from $2,300 2022-02-07
Diskstation Manager CRITICAL 9.8
CVE-2021-43927

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Security Management functionality in Synology D…

Fix: 6.2.4-25556-3 / 7.0.1-42218-2+
Fix from $2,300 2022-02-07
Mail Station HIGH 8.8
CVE-2021-43928

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in mail sending and receiving component in S…

Fix: 20211105+
Fix from $1,950 2022-02-07
Diskstation Manager MEDIUM 5.4
CVE-2021-43929

Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in work flow management in Synology …

Fix: 6.2.4-25556-3 / 7.0.1-42218-2+
Fix from $1,600 2022-02-07
Diskstation Manager CRITICAL 9.8
CVE-2021-43925

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskSt…

Fix: 6.2.4-25556-3 / 7.0.1-42218-2+
Fix from $2,300 2022-02-07
Diskstation Manager HIGH 7.5
CVE-2022-22680

Exposure of sensitive information to an unauthorized actor vulnerability in Web Server in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 all…

Fix: 6.2.4-25556-3 / 7.0.1-42218-2+
Fix from $1,950 2022-02-07
Diskstation Manager CRITICAL 9.8
CVE-2021-27649

Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers t…

Fix: 3.1-23033 / 6.2.3-25426-3+
Fix from $2,300 2021-06-23
Diskstation Manager HIGH 7.5
CVE-2021-29084

Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Security Advisor report managemen…

Fix: 3.1-23033 / 6.2.3-25426-3+
Fix from $1,950 2021-06-23
Diskstation Manager HIGH 7.5
CVE-2021-29085

Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file sharing management component…

Fix: 3.1-23033 / 6.2.3-25426-3+
Fix from $1,950 2021-06-23
Diskstation Manager HIGH 7.5
CVE-2021-29086

Exposure of sensitive information to an unauthorized actor vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426…

Fix: 3.1-23033 / 6.2.3-25426-3+
Fix from $1,950 2021-06-23
Diskstation Manager HIGH 7.5
CVE-2021-29087

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM…

Fix: 3.1-23033 / 6.2.3-25426-3+
Fix from $1,950 2021-06-23
Calendar HIGH 7.5
CVE-2021-34812

Use of hard-coded credentials vulnerability in php component in Synology Calendar before 2.4.0-0761 allows remote attackers to obtain sensitive infor…

Fix: 2.4.0-0761+
Fix from $1,950 2021-06-18
Download Station HIGH 8.8
CVE-2021-34809

Improper neutralization of special elements used in a command ('Command Injection') vulnerability in task management component in Synology Download S…

Fix: 3.8.16-3566+
Fix from $1,950 2021-06-18
Download Station HIGH 8.8
CVE-2021-34810

Improper privilege management vulnerability in cgi component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to exe…

Fix: 3.8.16-3566+
Fix from $1,950 2021-06-18
Media Server MEDIUM 5.3
CVE-2021-34808

Server-Side Request Forgery (SSRF) vulnerability in cgi component in Synology Media Server before 1.8.3-2881 allows remote attackers to access intran…

Fix: 1.8.3-2881+
Fix from $1,600 2021-06-18
Photo Station CRITICAL 9.8
CVE-2021-29089

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in thumbnail component in Synology Photo Station b…

Fix: 6.8.14-3500+
Fix from $2,300 2021-06-02
Photo Station MEDIUM 6.5
CVE-2021-29091

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file management component in Synology Photo Station b…

Fix: 6.8.14-3500+
Fix from $1,600 2021-06-02
Photo Station HIGH 7.2
CVE-2021-29090

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in PHP component in Synology Photo Station before …

Fix: 6.8.14-3500+
Fix from $1,950 2021-06-02
Media Server CRITICAL 9.8
CVE-2021-33180

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in cgi component in Synology Media Server before 1…

Fix: 1.8.1-2876+
Fix from $2,300 2021-06-01
Video Station CRITICAL 9.1
CVE-2021-33181

Server-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station before 2.4.10-1632 allows remote authenticated users t…

Fix: 2.4.10-1632+
Fix from $2,300 2021-06-01
Docker HIGH 7.9
CVE-2021-33183

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability container volume management component in Synology Docker…

Fix: 18.09.0-0515+
Fix from $1,950 2021-06-01
Download Station HIGH 7.7
CVE-2021-33184

Server-Side request forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.15-3563 allows remote authentic…

Fix: 3.8.15-3563+
Fix from $1,950 2021-06-01
Photo Station HIGH 8.8
CVE-2021-29092

Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote…

Fix: 6.8.14-3500+
Fix from $1,950 2021-06-01
Diskstation Manager HIGH 7.8
CVE-2021-29088

Improper limitation of a pathname to a restricted directory ('Path Traversal') in cgi component in Synology DiskStation Manager (DSM) before 6.2.4-25…

Fix: 6.2.4-25553+
Fix from $1,950 2021-06-01
Antivirus Essential HIGH 8.8
CVE-2021-27648

Externally controlled reference to a resource in another sphere in quarantine functionality in Synology Antivirus Essential before 1.4.8-2801 allows …

Fix: 1.4.8-2801+
Fix from $1,950 2021-04-28
Diskstation Manager HIGH 7.2
CVE-2021-29083

Improper neutralization of special elements used in an OS command in SYNO.Core.Network.PPPoE in Synology DiskStation Manager (DSM) before 6.2.3-25426…

Fix: 6.2.3-25426-3+
Fix from $1,950 2021-04-01
Diskstation Manager CRITICAL 9.8
CVE-2021-27646

Use After Free vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execut…

Fix: 6.2.3-25426-3+
Fix from $2,300 2021-03-12
Diskstation Manager CRITICAL 9.8
CVE-2021-27647

Out-of-bounds Read vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to ex…

Fix: 6.2.3-25426-3+
Fix from $2,300 2021-03-12
Diskstation Manager HIGH 8.1
CVE-2021-26569

Race Condition within a Thread vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote att…

Fix: 6.2.3-25426-3+
Fix from $1,950 2021-03-12
Diskstation Manager CRITICAL 9.0
CVE-2021-26566

Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-i…

Fix: 6.2.3-25426-3+
Fix from $2,300 2021-02-26