Vulnerability index

Browse CVEs

280 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Diskstation Manager HIGH 8.7
CVE-2021-26564

Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-…

Fix: 6.2.3-25426-3+
Fix from $1,950 2021-02-26
Diskstation Manager HIGH 8.1
CVE-2021-26562

Out-of-bounds write vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers…

Fix: 6.2.3-25426-3+
Fix from $1,950 2021-02-26
Diskstation Manager HIGH 7.8
CVE-2021-26567

Stack-based buffer overflow vulnerability in frontend/main.c in faad2 before 2.2.7.1 allow local attackers to execute arbitrary code via filename and…

Fix: 2.2.7.1 / 6.2.3-25426-3+
Fix from $1,950 2021-02-26
Diskstation Manager MEDIUM 6.7
CVE-2021-26563

Incorrect authorization vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to execute ar…

Fix: 6.2.4-25553+
Fix from $1,600 2021-02-26
Diskstation Manager MEDIUM 5.9
CVE-2021-26565

Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-…

Fix: 6.2.3-25426-3+
Fix from $1,600 2021-02-26
Diskstation Manager HIGH 8.1
CVE-2021-26561

Stack-based buffer overflow vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle a…

Fix: 6.2.3-25426-3+
Fix from $1,950 2021-02-26
Diskstation Manager HIGH 7.4
CVE-2021-26560

Cleartext transmission of sensitive information vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows…

Fix: 6.2.3-25426-3+
Fix from $1,950 2021-02-26
Safeaccess CRITICAL 9.8
CVE-2020-27660

SQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute arbitrary SQL commands via the…

Fix: 1.2.3-0234+
Fix from $2,300 2020-11-30
Router Manager CRITICAL 10.0
CVE-2020-27655

Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via i…

Fix: 1.2.4-8081+
Fix from $2,300 2020-10-29
Router Manager CRITICAL 9.8
CVE-2020-27654

Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands…

Fix: 1.2.4-8081+
Fix from $2,300 2020-10-29
Diskstation Manager HIGH 8.3
CVE-2020-27652

Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to sp…

Fix: 6.2.3-25426 / 6.2.3-25426-2+
Fix from $1,950 2020-10-29
Router Manager HIGH 8.3
CVE-2020-27653

Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof serv…

Fix: 1.2.4-8081+
Fix from $1,950 2020-10-29
Router Manager MEDIUM 6.1
CVE-2020-27658

Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easi…

Fix: 1.2.4-8081+
Fix from $1,600 2020-10-29
Router Manager MEDIUM 5.9
CVE-2020-27657

Cleartext transmission of sensitive information vulnerability in DDNS in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle att…

Fix: 1.2.4-8081+
Fix from $1,600 2020-10-29
Diskstation Manager CRITICAL 9.0
CVE-2020-27648

Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle a…

Fix: 6.2.3-25426 / 6.2.3-25426-2+
Fix from $2,300 2020-10-29
Router Manager CRITICAL 9.0
CVE-2020-27649

Improper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers…

Fix: 1.2.4-8081+
Fix from $2,300 2020-10-29
Router Manager HIGH 8.1
CVE-2020-27651

Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for re…

Fix: 1.2.4-8081+
Fix from $1,950 2020-10-29
Router Manager HIGH 7.5
CVE-2019-11823

CRLF injection vulnerability in Network Center in Synology Router Manager (SRM) before 1.2.3-8017-2 allows remote attackers to cause a denial of serv…

Fix: 1.2.3-8017-2+
Fix from $1,950 2020-05-04
Router Manager HIGH 8.8
CVE-2019-9501

The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a data length larger than 32 byte…

No fix yet
Fix from $1,950 2020-02-03
Router Manager HIGH 8.8
CVE-2019-9502

The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. If the vendor information element data length is larger than 164 bytes, a heap b…

Mitigation only
Fix from $1,950 2020-02-03
Photo Station CRITICAL 9.8
CVE-2019-11821

SQL injection vulnerability in synophoto_csPhotoDB.php in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to ex…

Fix: 6.3-2977 / 6.8.11-3489+
Fix from $2,300 2019-06-30
Calendar CRITICAL 9.8
CVE-2019-11829

OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar before 2.3.1-0617 allows remote attackers to execute arbitrar…

Fix: 2.3.1-0617+
Fix from $2,300 2019-06-30
Moments HIGH 8.8
CVE-2019-11826

Relative path traversal vulnerability in SYNO.PhotoTeam.Upload.Item in Synology Moments before 1.3.0-0691 allows remote authenticated users to upload…

Fix: 1.3.0-0691+
Fix from $1,950 2019-06-30
Photo Station MEDIUM 6.5
CVE-2019-11822

Relative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attack…

Fix: 6.3-2977 / 6.8.11-3489+
Fix from $1,600 2019-06-30
Calendar MEDIUM 5.4
CVE-2019-11825

Cross-site scripting (XSS) vulnerability in Event Editor in Synology Calendar before 2.3.0-0615 allows remote attackers to inject arbitrary web scrip…

Fix: 2.3.0-0615+
Fix from $1,600 2019-06-30
Note Station MEDIUM 5.4
CVE-2019-11827

Cross-site scripting (XSS) vulnerability in SYNO.NoteStation.Shard in Synology Note Station before 2.5.3-0863 allows remote attackers to inject arbit…

Fix: 2.5.3-0863+
Fix from $1,600 2019-06-30
Office MEDIUM 5.4
CVE-2019-11828

Cross-site scripting (XSS) vulnerability in Chart in Synology Office before 3.1.4-2771 allows remote authenticated users to inject arbitrary web scri…

Fix: 3.1.4-2771+
Fix from $1,600 2019-06-30
Calendar MEDIUM 5.5
CVE-2019-11820

Information exposure through process environment vulnerability in Synology Calendar before 2.3.3-0620 allows local users to obtain credentials via cm…

Fix: 2.3.3-0620+
Fix from $1,600 2019-05-09
Diskstation Manager HIGH 8.8
CVE-2018-13284

Command injection vulnerability in ftpd in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to execute arbitra…

Fix: 5.2-5967-8 / 6.0.3-8754-8+
Fix from $1,950 2019-04-01
Router Manager HIGH 8.8
CVE-2018-13285

Command injection vulnerability in ftpd in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users to execute arbitrary O…

Fix: 1.1.7-6941-1+
Fix from $1,950 2019-04-01