Vulnerability index

Browse CVEs

280 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Router Manager HIGH 7.2
CVE-2017-12078

Command injection vulnerability in EZ-Internet in Synology Router Manager (SRM) before 1.1.6-6931 allows remote authenticated users to execute arbitr…

Fix: 1.1.6-6931+
Fix from $1,950 2018-06-08
File Station MEDIUM 5.4
CVE-2018-8923

Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology File Station before 1.1.4-0122 allows remote authenticated users to inject…

Fix: 1.1.4-0122+
Fix from $1,600 2018-06-05
Office MEDIUM 5.4
CVE-2018-8924

Cross-site scripting (XSS) vulnerability in Title Tootip in Synology Office before 3.0.3-2143 allows remote authenticated users to inject arbitrary w…

Fix: 3.0.3-2143+
Fix from $1,600 2018-06-05
Drive Server MEDIUM 6.5
CVE-2018-8922

Improper access control vulnerability in Synology Drive before 1.0.2-10275 allows remote authenticated users to access non-shared files or folders vi…

Mitigation only
Fix from $1,600 2018-06-01
Drive Server MEDIUM 5.4
CVE-2018-8921

Cross-site scripting (XSS) vulnerability in File Sharing Notify Toast in Synology Drive before 1.0.2-10275 allows remote authenticated users to injec…

Fix: 1.0.2-10275+
Fix from $1,600 2018-06-01
Media Server CRITICAL 9.8
CVE-2018-8914

SQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote attackers to execute arbitrary S…

Fix: 1.4-2654 / 1.7.6-2842+
Fix from $2,300 2018-05-10
Drive Server MEDIUM 5.4
CVE-2018-8910

Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology Drive before 1.0.1-10253 allows remote authenticated users to inject arbit…

Fix: 1.0.1-10253+
Fix from $1,600 2018-05-10
Calendar MEDIUM 5.4
CVE-2018-8915

Cross-site scripting (XSS) vulnerability in Notification Center in Synology Calendar before 2.1.1-0502 allows remote authenticated users to inject ar…

Fix: 2.1.1-0502+
Fix from $1,600 2018-05-10
Note Station MEDIUM 5.4
CVE-2018-8911

Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology Note Station before 2.5.1-0844 allows remote authenticated users to inject…

Fix: 2.5.1-0844+
Fix from $1,600 2018-05-09
Note Station MEDIUM 5.4
CVE-2018-8912

Cross-site scripting (XSS) vulnerability in SYNO.NoteStation.Note in Synology Note Station before 2.5.1-0844 allows remote authenticated users to inj…

Fix: 2.5.1-0844+
Fix from $1,600 2018-05-09
Photo Station HIGH 8.8
CVE-2017-16772

Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote…

Fix: 6.3-2971 / 6.8.3-3463+
Fix from $1,950 2018-03-22
Photo Station MEDIUM 6.1
CVE-2017-16771

Cross-site scripting (XSS) vulnerability in Log Viewer in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote attackers to inj…

Fix: 6.3-2971 / 6.8.3-3463+
Fix from $1,600 2018-03-22
Surveillance Station MEDIUM 6.5
CVE-2017-16770

File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.…

Fix: 8.1.2-5469+
Fix from $1,600 2018-02-27
Surveillance Station MEDIUM 5.4
CVE-2017-16767

Cross-site scripting (XSS) vulnerability in User Profile in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to inje…

Fix: 8.1.2-5469+
Fix from $1,600 2018-02-27
Photo Station MEDIUM 5.3
CVE-2017-16769

Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from pa…

Mitigation only
Fix from $1,600 2018-02-23
Chat MEDIUM 6.5
CVE-2017-15886

Server-side request forgery (SSRF) vulnerability in Link Preview in Synology Chat before 2.0.0-1124 allows remote authenticated users to download arb…

Fix: 2.0.0-1124+
Fix from $1,600 2017-12-28
Chat MEDIUM 5.4
CVE-2017-15892

Multiple cross-site scripting (XSS) vulnerabilities in Slash Command Creator in Synology Chat before 2.0.0-1124 allow remote authenticated users to i…

Fix: 2.0.0-1124+
Fix from $1,600 2017-12-28
Diskstation Manager MEDIUM 6.5
CVE-2017-16766

An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows loc…

Fix: 6.0.3-8754-6 / 6.1.4-15217+
Fix from $1,600 2017-12-22
Photo Station MEDIUM 5.4
CVE-2017-12072

Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.8.0-3456 allows remote authenticated users to i…

Fix: 6.8.0-3456+
Fix from $1,600 2017-12-20
Calendar MEDIUM 6.5
CVE-2017-15891

Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authenticated users to modify calend…

Fix: 2.0.1-0242+
Fix from $1,600 2017-12-08
File Station MEDIUM 6.5
CVE-2017-15893

Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology File Station before 1.1.1-0099 allows remote authenticated users to wri…

Fix: 1.1.1-0099+
Fix from $1,600 2017-12-08
Diskstation Manager MEDIUM 6.5
CVE-2017-15894

Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology DiskStation Manager (DSM) 6.0.x before 6.0.3-8754-3 and before 5.2-5967…

Fix: 5.2-5967-6 / 6.0.3-8754-3+
Fix from $1,600 2017-12-08
Router Manager MEDIUM 6.5
CVE-2017-15895

Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology Router Manager (SRM) before 1.1.5-6542-4 allows remote authenticated us…

Fix: 1.1.5-6542-4+
Fix from $1,600 2017-12-08
Diskstation Manager HIGH 8.8
CVE-2017-15889EPSS 72%

Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arb…

Fix: 5.2-5967-5+
Fix from $1,950 2017-12-04
Photo Station HIGH 7.5
CVE-2017-12079

Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allow…

Fix: 6.3-2970 / 6.8.1-3458+
Fix from $1,950 2017-12-04
Photo Station MEDIUM 5.3
CVE-2017-12080

An information exposure vulnerability in default HTTP configuration file in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remot…

Fix: 6.3-2970 / 6.8.1-3458+
Fix from $1,600 2017-12-04
Carddav Server CRITICAL 9.8
CVE-2017-15887

An improper restriction of excessive authentication attempts vulnerability in /principals in Synology CardDAV Server before 6.0.7-0085 allows remote …

Fix: 6.0.7-0085+
Fix from $2,300 2017-11-07
Audio Station MEDIUM 5.4
CVE-2017-15888

Cross-site scripting (XSS) vulnerability in Custom Internet Radio List in Synology Audio Station before 6.3.0-3260 allows remote authenticated attack…

Fix: 6.3.0-3260+
Fix from $1,600 2017-10-30
Photo Station CRITICAL 9.8
CVE-2017-11161

Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL comma…

Fix: after 6.7.3-3432
Fix from $2,300 2017-09-08
Photo Station MEDIUM 6.5
CVE-2017-11162

Directory traversal vulnerability in synphotoio in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to read ar…

Fix: after 6.7.3-3432
Fix from $1,600 2017-09-08