Vulnerability index

Browse CVEs

280 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.9 CVE-2024-53287 Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functionality in Synology Router Ma… Router Manager 1.3.1-9346+ Fix from $1,6002025-07-23 MEDIUM 6.5 CVE-2025-4679 A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive information via unspecified vec… Active Backup For Microsoft 365 Mitigation only Fix from $1,6002025-05-16 HIGH 7.5 CVE-2025-1021 Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows re… Diskstation Manager 7.1.1-42962-8 / 7.2.1-69057-7+ Fix from $1,9502025-04-23 HIGH 7.5 CVE-2024-50630EPSS 23% Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26… Drive Server 3.0.4-12699 / 3.2.1-23280+ Fix from $1,9502025-03-19 HIGH 7.5 CVE-2024-50631EPSS 25% Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in the system syncing daemon in Synology Drive Ser… Drive Server 3.0.4-12699 / 3.2.1-23280+ Fix from $1,9502025-03-19 MEDIUM 5.3 CVE-2024-50629EPSS 28% Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStati… Beestation Os 7.1.1-42962-7 / 7.2.1-69057-6+ Fix from $1,6002025-03-19 CRITICAL 9.8 CVE-2024-11131 A vulnerability regarding out-of-bounds read is found in the video interface. This allows remote attackers to execute arbitrary code via unspecified … Tc500 Firmware 1.2.0-0525+ Fix from $2,3002025-03-19 CRITICAL 10.0 CVE-2024-10442 Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423 and Synolo… Unified Controller 1.2.2-0353 / 1.3.0-0423+ Fix from $2,3002025-03-19 HIGH 7.5 CVE-2024-10444 Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2… Diskstation Manager 7.1.1-42962-8 / 7.2.1-69057-7+ Fix from $1,9502025-03-19 MEDIUM 5.3 CVE-2024-10445 Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation M… Beestation Os 6.2.4-25556-8 / 7.2.1-69057-6+ Fix from $1,6002025-03-19 CRITICAL 9.8 CVE-2024-10441 Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskS… Beestation Os 7.2.1-69057-6 / 7.2.2-72806-1+ Fix from $2,3002025-03-19 MEDIUM 6.5 CVE-2024-47265 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount functionality in Synology Acti… Active Backup For Business Agent 2.7.1-3234 / 2.7.1-13234+ Fix from $1,6002025-02-13 MEDIUM 6.5 CVE-2024-47264 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functionality in Synology Active Backup… Active Backup For Business Agent 2.7.1-3234 / 2.7.1-13234+ Fix from $1,6002025-02-13 HIGH 7.5 CVE-2024-4464 Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-2680, 2.0.5-3152 and 2.2.0-33… Media Server 1.4-2680 / 2.0.5-3152+ Fix from $1,9502024-12-18 MEDIUM 5.9 CVE-2024-53283 Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Router Port Forward functionality in Synology R… Router Manager 1.3.1-9346+ Fix from $1,6002024-12-09 MEDIUM 5.9 CVE-2024-53284 Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect Setting functionality in Synology … Router Manager 1.3.1-9346+ Fix from $1,6002024-12-09 MEDIUM 5.9 CVE-2024-53285 Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in DDNS Record functionality in Synology Router Ma… Router Manager 1.3.1-9346+ Fix from $1,6002024-12-09 MEDIUM 5.9 CVE-2024-53279 Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in file station functionality in Synology Router M… Router Manager 1.3.1-9346+ Fix from $1,6002024-12-09 MEDIUM 5.9 CVE-2024-53280 Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in network center policy route functionality in Sy… Router Manager 1.3.1-9346+ Fix from $1,6002024-12-09 MEDIUM 5.9 CVE-2024-53281 Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Network WOL functionality in Synology Router Ma… Router Manager 1.3.1-9346+ Fix from $1,6002024-12-09 MEDIUM 5.9 CVE-2024-53282 Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect MAC Filter functionality in Synolo… Router Manager 1.3.1-9346+ Fix from $1,6002024-12-09 HIGH 8.1 CVE-2024-11398 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality in Synology Router Manager (S… Router Manager 1.3.1-9346+ Fix from $1,9502024-12-04 CRITICAL 9.8 CVE-2024-10443EPSS 28% Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePho… Photos 1.0.2-10026 / 1.1.0-10053+ Fix from $2,3002024-11-15 MEDIUM 5.5 CVE-2023-52949 Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for Business Agent before 2.7.0-… Active Backup For Business Agent 2.7.0-3221+ Fix from $1,6002024-09-26 MEDIUM 5.3 CVE-2023-52950 Missing encryption of sensitive data vulnerability in login component in Synology Active Backup for Business Agent before 2.7.0-3221 allows adjacent … Active Backup For Business Agent 2.7.0-3221+ Fix from $1,6002024-09-26 MEDIUM 5.0 CVE-2023-52948 Missing encryption of sensitive data vulnerability in settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows lo… Active Backup For Business Agent 2.7.0-3221+ Fix from $1,6002024-09-26 HIGH 8.2 CVE-2023-52946 Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in vss service component in Synology Drive Client before 3.5.0-1… Drive Client 3.5.0-16084+ Fix from $1,9502024-09-26 MEDIUM 6.7 CVE-2022-49039 Out-of-bounds write vulnerability in backup task management functionality in Synology Drive Client before 3.4.0-15721 allows local users with adminis… Drive Client 3.4.0-15721+ Fix from $1,6002024-09-26 HIGH 7.8 CVE-2022-49038 Inclusion of functionality from untrusted control sphere vulnerability in OpenSSL DLL component in Synology Drive Client before 3.3.0-15082 allows lo… Drive Client 3.3.0-15082+ Fix from $1,9502024-09-26 MEDIUM 6.5 CVE-2022-49037 Insertion of sensitive information into log file vulnerability in proxy settings component in Synology Drive Client before 3.3.0-15082 allows remote … Drive Client 3.3.0-15082+ Fix from $1,6002024-09-26