Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2022-49042
An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 …
Hyper Backup Explorer
3.0.1-0156+
MEDIUM 5.9
CVE-2023-52951
A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers t…
Note Station Client
2.2.4-703+
HIGH 7.8
CVE-2022-49036
An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Me…
Active Backup For Business Recovery Media Creator
2.5.0-2081+
HIGH 8.6
CVE-2025-30028
A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.
Active Backup For Business
Mitigation only
MEDIUM 5.6
CVE-2025-66592
An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files w…
Active Backup For Business Agent
3.1.0-4967+
MEDIUM 5.6
CVE-2025-66593
An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content…
Assistant
7.0.6-50085+
MEDIUM 5.5
CVE-2026-2237
A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 all…
Storage Manager
1.0.1-1100+
CRITICAL 9.8
CVE-2025-12686
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allo…
Beestation Os
1.3.2+
CRITICAL 9.8
CVE-2025-13392
Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-…
Diskstation Manager
7.2.2-72806-5+
HIGH 7.5
CVE-2025-14713
An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers t…
C2 Identity Edge Server
1.76.0-0307+
MEDIUM 5.9
CVE-2025-10466
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Synology Safe Access before 1.3.…
Safe Access
1.3.1-0329+
MEDIUM 5.6
CVE-2025-13593
Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted c…
Activeprotect Agent
1.1.0-0439+
MEDIUM 5.4
CVE-2025-13167
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts befo…
Contacts
1.0.10-20659+
MEDIUM 6.8
CVE-2024-11399
Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for desktop before 1.3.2-13814 allow…
Beedrive
1.3.2-13814+
HIGH 7.8
CVE-2023-52945
Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to exe…
Beedrive
1.3.2-13814+
HIGH 8.1
CVE-2021-47961
A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user'…
Ssl Vpn Client
1.4.5-0684+
MEDIUM 6.5
CVE-2021-47960
A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access fi…
Ssl Vpn Client
1.4.5-0684+
HIGH 7.3
CVE-2026-3091
An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files and…
Presto Client
2.1.3-0672+
MEDIUM 5.6
CVE-2025-8074
Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users to write arbitrary files wit…
Beedrive
1.4.3-13973+
HIGH 7.8
CVE-2025-54160
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.…
Beedrive
1.4.2-13960+
HIGH 7.5
CVE-2025-54159
Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitrary files…
Beedrive
1.4.2-13960+
HIGH 7.8
CVE-2025-54158
Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to exec…
Beedrive
1.4.2-13960+
MEDIUM 6.3
CVE-2025-2848
A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical…
Mail Server
1.7.6-10676 / 1.7.6-20676+
HIGH 7.2
CVE-2025-29846
A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.
Router Manager
1.3.1-9346+
MEDIUM 5.4
CVE-2025-29843
A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.
Router Manager
1.3.1-9346+
CRITICAL 9.6
CVE-2024-45538
Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Sy…
Diskstation Manager
3.1.4-23079 / 7.2.1-69057-2+
HIGH 8.8
CVE-2024-5401
Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before 7.1.1-42962-8 a…
Diskstation Manager
3.1.4-23079 / 7.2.1-69057-2+
HIGH 7.5
CVE-2024-45539
Out-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified C…
Diskstation Manager
3.1.4-23079 / 7.2.1-69057-2+
MEDIUM 5.9
CVE-2024-53288
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in NTP Region functionality in Synology Router Man…
Router Manager
1.3.1-9346+
HIGH 7.2
CVE-2024-53286
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record functionality in Synology Rou…
Router Manager
1.3.1-9346+