Vulnerability index

Browse CVEs

280 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2024-39348 Download of code without integrity check vulnerability in AirPrint functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346… Router Manager 1.2.5-8227 / 1.3.1-9346+ Fix from $1,9502024-06-28 HIGH 7.5 CVE-2024-39350 A vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows man-in-the-middle attackers to obtain pri… Tc500 Firmware 1.0.7-0298+ Fix from $1,9502024-06-28 MEDIUM 5.9 CVE-2024-39347 Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows m… Router Manager 1.2.5-8227 / 1.3.1-9346+ Fix from $1,6002024-06-28 CRITICAL 9.8 CVE-2024-39349 A vulnerability regarding buffer copy without checking size of input ('Classic Buffer Overflow') is found in the libjansson component and it does not… Bc500 Firmware 1.0.7-0298+ Fix from $2,3002024-06-28 HIGH 7.2 CVE-2024-39351 A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the NTP configuratio… Bc500 Firmware 1.0.7-0298+ Fix from $1,9502024-06-28 MEDIUM 5.3 CVE-2023-47803 A vulnerability regarding improper limitation of a pathname to a restricted directory ('Path Traversal') is found in the Language Settings functional… Bc500 Firmware 1.0.7-0298+ Fix from $1,6002024-06-28 HIGH 7.2 CVE-2023-47802 A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the IP block functio… Bc500 Firmware 1.0.7-0298+ Fix from $1,9502024-06-28 MEDIUM 6.5 CVE-2024-5463 A vulnerability regarding buffer copy without checking the size of input ('Classic Buffer Overflow') has been found in the login component. This allo… Bc500 Firmware 1.1.1-0383+ Fix from $1,6002024-06-04 CRITICAL 9.9 CVE-2024-29241 Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authe… Surveillance Station 9.2.0-9289 / 9.2.0-11289+ Fix from $2,3002024-03-28 MEDIUM 5.4 CVE-2024-29239 Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Recording.CountByCategory webapi component in S… Surveillance Station 9.2.0-9289 / 9.2.0-11289+ Fix from $1,6002024-03-28 MEDIUM 5.4 CVE-2024-29237 Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in ActionRule.Delete webapi component in Synology … Surveillance Station 9.2.0-9289 / 9.2.0-11289+ Fix from $1,6002024-03-28 MEDIUM 5.4 CVE-2024-29238 Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log.CountByCategory webapi component in Synolog… Surveillance Station 9.2.0-9289 / 9.2.0-11289+ Fix from $1,6002024-03-28 MEDIUM 5.4 CVE-2024-29236 Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in AudioPattern.Delete webapi component in Synolog… Surveillance Station 9.2.0-9289 / 9.2.0-11289+ Fix from $1,6002024-03-28 MEDIUM 5.4 CVE-2024-29235 Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in IOModule.EnumLog webapi component in Synology S… Surveillance Station 9.2.0-9289 / 9.2.0-11289+ Fix from $1,6002024-03-28 MEDIUM 5.4 CVE-2024-29233 Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Emap.Delete webapi component in Synology Survei… Surveillance Station 9.2.0-9289 / 9.2.0-11289+ Fix from $1,6002024-03-28 MEDIUM 5.4 CVE-2024-29234 Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi component in Synology Surveil… Surveillance Station 9.2.0-9289 / 9.2.0-11289+ Fix from $1,6002024-03-28 MEDIUM 5.4 CVE-2024-29232 Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Alert.Enum webapi component in Synology Surveil… Surveillance Station 9.2.0-9289 / 9.2.0-11289+ Fix from $1,6002024-03-28 MEDIUM 5.4 CVE-2024-29231 Improper validation of array index vulnerability in UserPrivilege.Enum webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-… Surveillance Station 9.2.0-9289 / 9.2.0-11289+ Fix from $1,6002024-03-28 MEDIUM 5.4 CVE-2024-29230 Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in SnapShot.CountByCategory webapi component in Sy… Surveillance Station 9.2.0-9289 / 9.2.0-11289+ Fix from $1,6002024-03-28 HIGH 7.7 CVE-2024-29229 Missing authorization vulnerability in GetLiveViewPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows rem… Surveillance Station 9.2.0-9289 / 9.2.0-11289+ Fix from $1,9502024-03-28 HIGH 7.7 CVE-2024-29228 Missing authorization vulnerability in GetStmUrlPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remot… Surveillance Station 9.2.0-9289 / 9.2.0-11289+ Fix from $1,9502024-03-28 MEDIUM 5.4 CVE-2024-29227 Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Layout.LayoutSave webapi component in Synology … Surveillance Station 9.2.0-9289 / 9.2.0-11289+ Fix from $1,6002024-03-28 MEDIUM 5.4 CVE-2024-0854 URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manager (DSM) before 6.2.4-25556-8… Diskstation Manager 7.2.1-69057-2+ Fix from $1,6002024-01-24 MEDIUM 5.5 CVE-2023-5748 Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology SSL VPN Client before 1.4.7-0687 al… Ssl Vpn Client 1.4.7-0687+ Fix from $1,6002023-11-07 CRITICAL 9.8 CVE-2023-5746 A vulnerability regarding use of externally-controlled format string is found in the cgi component. This allows remote attackers to execute arbitrary… Bc500 Firmware 1.0.5-0185+ Fix from $2,3002023-10-25 HIGH 8.8 CVE-2023-41738 Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Directory Domain Functionality in Synolog… Router Manager 1.3.1-9346-6+ Fix from $1,9502023-08-31 HIGH 7.5 CVE-2023-41741 Exposure of sensitive information to an unauthorized actor vulnerability in cgi component in Synology Router Manager (SRM) before 1.3.1-9346-6 allows… Router Manager 1.3.1-9346-6+ Fix from $1,9502023-08-31 MEDIUM 6.5 CVE-2023-41739 Uncontrolled resource consumption vulnerability in File Functionality in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote authenticate… Router Manager 1.3.1-9346-6+ Fix from $1,6002023-08-31 MEDIUM 5.3 CVE-2023-41740 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology Router Manager (SRM) before… Router Manager 1.3.1-9346-6+ Fix from $1,6002023-08-31 HIGH 7.5 CVE-2023-2729 Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7.2-64561 allows remo… Diskstation Manager Unified Controller 1.3.1-9346 / 7.2-64561+ Fix from $1,9502023-06-13