Vulnerability index

Browse CVEs

280 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2021-43926 Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskSt… Diskstation Manager 6.2.4-25556-3 / 7.0.1-42218-2+ Fix from $2,3002022-02-07 CRITICAL 9.8 CVE-2021-43927 Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Security Management functionality in Synology D… Diskstation Manager 6.2.4-25556-3 / 7.0.1-42218-2+ Fix from $2,3002022-02-07 HIGH 8.8 CVE-2021-43928 Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in mail sending and receiving component in S… Mail Station 20211105+ Fix from $1,9502022-02-07 MEDIUM 5.4 CVE-2021-43929 Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in work flow management in Synology … Diskstation Manager 6.2.4-25556-3 / 7.0.1-42218-2+ Fix from $1,6002022-02-07 CRITICAL 9.8 CVE-2021-43925 Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskSt… Diskstation Manager 6.2.4-25556-3 / 7.0.1-42218-2+ Fix from $2,3002022-02-07 HIGH 7.5 CVE-2022-22680 Exposure of sensitive information to an unauthorized actor vulnerability in Web Server in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 all… Diskstation Manager 6.2.4-25556-3 / 7.0.1-42218-2+ Fix from $1,9502022-02-07 CRITICAL 9.8 CVE-2021-27649 Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers t… Diskstation Manager 3.1-23033 / 6.2.3-25426-3+ Fix from $2,3002021-06-23 HIGH 7.5 CVE-2021-29084 Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Security Advisor report managemen… Diskstation Manager 3.1-23033 / 6.2.3-25426-3+ Fix from $1,9502021-06-23 HIGH 7.5 CVE-2021-29085 Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file sharing management component… Diskstation Manager 3.1-23033 / 6.2.3-25426-3+ Fix from $1,9502021-06-23 HIGH 7.5 CVE-2021-29086 Exposure of sensitive information to an unauthorized actor vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426… Diskstation Manager 3.1-23033 / 6.2.3-25426-3+ Fix from $1,9502021-06-23 HIGH 7.5 CVE-2021-29087 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM… Diskstation Manager 3.1-23033 / 6.2.3-25426-3+ Fix from $1,9502021-06-23 HIGH 7.5 CVE-2021-34812 Use of hard-coded credentials vulnerability in php component in Synology Calendar before 2.4.0-0761 allows remote attackers to obtain sensitive infor… Calendar 2.4.0-0761+ Fix from $1,9502021-06-18 HIGH 8.8 CVE-2021-34809 Improper neutralization of special elements used in a command ('Command Injection') vulnerability in task management component in Synology Download S… Download Station 3.8.16-3566+ Fix from $1,9502021-06-18 HIGH 8.8 CVE-2021-34810 Improper privilege management vulnerability in cgi component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to exe… Download Station 3.8.16-3566+ Fix from $1,9502021-06-18 MEDIUM 5.3 CVE-2021-34808 Server-Side Request Forgery (SSRF) vulnerability in cgi component in Synology Media Server before 1.8.3-2881 allows remote attackers to access intran… Media Server 1.8.3-2881+ Fix from $1,6002021-06-18 CRITICAL 9.8 CVE-2021-29089 Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in thumbnail component in Synology Photo Station b… Photo Station 6.8.14-3500+ Fix from $2,3002021-06-02 MEDIUM 6.5 CVE-2021-29091 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file management component in Synology Photo Station b… Photo Station 6.8.14-3500+ Fix from $1,6002021-06-02 HIGH 7.2 CVE-2021-29090 Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in PHP component in Synology Photo Station before … Photo Station 6.8.14-3500+ Fix from $1,9502021-06-02 CRITICAL 9.8 CVE-2021-33180 Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in cgi component in Synology Media Server before 1… Media Server 1.8.1-2876+ Fix from $2,3002021-06-01 CRITICAL 9.1 CVE-2021-33181 Server-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station before 2.4.10-1632 allows remote authenticated users t… Video Station 2.4.10-1632+ Fix from $2,3002021-06-01 HIGH 7.9 CVE-2021-33183 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability container volume management component in Synology Docker… Docker 18.09.0-0515+ Fix from $1,9502021-06-01 HIGH 7.7 CVE-2021-33184 Server-Side request forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.15-3563 allows remote authentic… Download Station 3.8.15-3563+ Fix from $1,9502021-06-01 HIGH 8.8 CVE-2021-29092 Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote… Photo Station 6.8.14-3500+ Fix from $1,9502021-06-01 HIGH 7.8 CVE-2021-29088 Improper limitation of a pathname to a restricted directory ('Path Traversal') in cgi component in Synology DiskStation Manager (DSM) before 6.2.4-25… Diskstation Manager 6.2.4-25553+ Fix from $1,9502021-06-01 HIGH 8.8 CVE-2021-27648 Externally controlled reference to a resource in another sphere in quarantine functionality in Synology Antivirus Essential before 1.4.8-2801 allows … Antivirus Essential 1.4.8-2801+ Fix from $1,9502021-04-28 HIGH 7.2 CVE-2021-29083 Improper neutralization of special elements used in an OS command in SYNO.Core.Network.PPPoE in Synology DiskStation Manager (DSM) before 6.2.3-25426… Diskstation Manager 6.2.3-25426-3+ Fix from $1,9502021-04-01 CRITICAL 9.8 CVE-2021-27646 Use After Free vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execut… Diskstation Manager 6.2.3-25426-3+ Fix from $2,3002021-03-12 CRITICAL 9.8 CVE-2021-27647 Out-of-bounds Read vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to ex… Diskstation Manager 6.2.3-25426-3+ Fix from $2,3002021-03-12 HIGH 8.1 CVE-2021-26569 Race Condition within a Thread vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote att… Diskstation Manager 6.2.3-25426-3+ Fix from $1,9502021-03-12 CRITICAL 9.0 CVE-2021-26566 Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-i… Diskstation Manager 6.2.3-25426-3+ Fix from $2,3002021-02-26