Vulnerability index

Browse CVEs

280 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2023-0142 Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-4… Diskstation Manager Unified Controller 1.3.1-9346 / 7.1-42661+ Fix from $1,9502023-06-13 CRITICAL 9.8 CVE-2023-32956 Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in CGI component in Synology Router Manager … Router Manager 1.2.5-8227-6 / 1.3.1-9346-3+ Fix from $2,3002023-05-16 HIGH 8.1 CVE-2023-32955 Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DHCP Client Functionality in Synology Rou… Router Manager 1.2.5-8227-6 / 1.3.1-9346-3+ Fix from $1,9502023-05-16 CRITICAL 9.8 CVE-2023-0077 Integer overflow or wraparound vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote att… Router Manager 1.2.5-8227-6 / 1.3.1-9346-3+ Fix from $2,3002023-01-05 HIGH 7.5 CVE-2022-43932 Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in CGI component in Synology Router … Router Manager 1.2.5-8227-6 / 1.3.1-9346-3+ Fix from $1,9502023-01-05 CRITICAL 10.0 CVE-2022-43931EPSS 17% Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server before 1.4.3-0534 and 1.4.4-0635 allows remote attacker… Vpn Plus Server 1.4.3-0534 / 1.4.4-0635+ Fix from $2,3002023-01-03 HIGH 8.8 CVE-2022-43749 Improper privilege management vulnerability in summary report management in Synology Presto File Server before 2.1.2-1601 allows remote authenticated… Presto File Server 2.1.2-1601+ Fix from $1,9502022-10-26 HIGH 7.5 CVE-2022-43748 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file operation management in Synology Presto File Ser… Presto File Server 2.1.2-1601+ Fix from $1,9502022-10-26 CRITICAL 9.1 CVE-2022-27623 Missing authentication for critical function vulnerability in iSCSI management functionality in Synology DiskStation Manager (DSM) before 7.1-42661 a… Diskstation Manager 7.1-42661+ Fix from $2,3002022-10-25 HIGH 7.5 CVE-2022-3576 A vulnerability regarding out-of-bounds read is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote att… Diskstation Manager 7.1.1-42962-2+ Fix from $1,9502022-10-20 CRITICAL 9.8 CVE-2022-27625 A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the message processing functionality of… Diskstation Manager 7.1.1-42962-2+ Fix from $2,3002022-10-20 HIGH 8.1 CVE-2022-27626 A vulnerability regarding concurrent execution using shared resource with improper synchronization ('Race Condition') is found in the session process… Diskstation Manager 7.1.1-42962-2+ Fix from $1,9502022-10-20 CRITICAL 9.8 CVE-2022-27624 A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the packet decryption functionality of … Diskstation Manager 7.1.1-42962-2+ Fix from $2,3002022-10-20 MEDIUM 6.5 CVE-2022-27618 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Storage Analyzer before … Storage Analyzer 2.0.1-0214 / 2.1.0-0390+ Fix from $1,6002022-08-03 MEDIUM 5.9 CVE-2022-27619 Cleartext transmission of sensitive information vulnerability in authentication management in Synology Note Station Client before 2.2.2-609 allows ma… Note Station 2.2.2-609+ Fix from $1,6002022-08-03 HIGH 7.2 CVE-2022-27616 Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in webapi component in Synology DiskStation … Diskstation Manager 6.2.4-25556-5 / 7.0.1-42218-3+ Fix from $1,9502022-08-03 HIGH 8.1 CVE-2022-27611 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Audio Station before 6.5… Audio Station 6.5.4-3367+ Fix from $1,9502022-07-28 HIGH 7.5 CVE-2022-27614 Exposure of sensitive information to an unauthorized actor vulnerability in web server in Synology Media Server before 1.8.1-2876 allows remote attac… Media Server 1.4-2665 / 1.8.1-2876+ Fix from $1,9502022-07-28 CRITICAL 9.8 CVE-2022-22683 Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allo… Media Server 1.4-2665 / 1.8.1-2876+ Fix from $2,3002022-07-28 CRITICAL 9.8 CVE-2022-27612 Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Audio Station before 6.5.4-3367 all… Audio Station 6.5.4-3367+ Fix from $2,3002022-07-28 HIGH 8.8 CVE-2022-22684 Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in task management component in Synology Dis… Diskstation Manager 6.2.4-25553+ Fix from $1,9502022-07-28 HIGH 8.8 CVE-2022-27613 Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in webapi component in Synology CardDAV Server bef… Carddav Server 6.0.10-0153+ Fix from $1,9502022-07-28 HIGH 8.1 CVE-2022-22685 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology WebDAV Server before 2.4… Webdav Server 2.4.0-0062+ Fix from $1,9502022-07-28 HIGH 8.1 CVE-2022-27615 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology DNS Server before 2.2.2-502… Dns Server 2.2.2-5027+ Fix from $1,9502022-07-28 HIGH 8.1 CVE-2022-27610 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM… Diskstation Manager 6.2.3-25423+ Fix from $1,9502022-07-27 HIGH 8.0 CVE-2022-22686 Cross-Site Request Forgery (CSRF) vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to hijac… Calendar 2.3.4-0631+ Fix from $1,9502022-07-26 MEDIUM 5.4 CVE-2022-22682 Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Event Management in Synology Calendar before 2.… Calendar 2.4.5-10930+ Fix from $1,6002022-07-12 HIGH 7.5 CVE-2022-22681 Session fixation vulnerability in access control management in Synology Photo Station before 6.8.16-3506 allows remote attackers to bypass security c… Photo Station 6.8.16-3506+ Fix from $1,9502022-07-06 CRITICAL 9.8 CVE-2022-22687 Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager … Diskstation Manager 3.1-23033 / 6.2.3-25426-3+ Fix from $2,3002022-03-25 HIGH 8.8 CVE-2022-22688 Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology DiskStati… Diskstation Manager 6.2.4-25556-2 / 7.0.1-42214+ Fix from $1,9502022-03-25