Vulnerability index

Browse CVEs

280 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.7 CVE-2021-26564 Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-… Diskstation Manager 6.2.3-25426-3+ Fix from $1,9502021-02-26 HIGH 8.1 CVE-2021-26562 Out-of-bounds write vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers… Diskstation Manager 6.2.3-25426-3+ Fix from $1,9502021-02-26 HIGH 7.8 CVE-2021-26567 Stack-based buffer overflow vulnerability in frontend/main.c in faad2 before 2.2.7.1 allow local attackers to execute arbitrary code via filename and… Diskstation Manager 2.2.7.1 / 6.2.3-25426-3+ Fix from $1,9502021-02-26 MEDIUM 6.7 CVE-2021-26563 Incorrect authorization vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to execute ar… Diskstation Manager 6.2.4-25553+ Fix from $1,6002021-02-26 MEDIUM 5.9 CVE-2021-26565 Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-… Diskstation Manager 6.2.3-25426-3+ Fix from $1,6002021-02-26 HIGH 8.1 CVE-2021-26561 Stack-based buffer overflow vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle a… Diskstation Manager 6.2.3-25426-3+ Fix from $1,9502021-02-26 HIGH 7.4 CVE-2021-26560 Cleartext transmission of sensitive information vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows… Diskstation Manager 6.2.3-25426-3+ Fix from $1,9502021-02-26 CRITICAL 9.8 CVE-2020-27660 SQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute arbitrary SQL commands via the… Safeaccess 1.2.3-0234+ Fix from $2,3002020-11-30 CRITICAL 10.0 CVE-2020-27655 Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via i… Router Manager 1.2.4-8081+ Fix from $2,3002020-10-29 CRITICAL 9.8 CVE-2020-27654 Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands… Router Manager 1.2.4-8081+ Fix from $2,3002020-10-29 HIGH 8.3 CVE-2020-27652 Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to sp… Diskstation Manager 6.2.3-25426 / 6.2.3-25426-2+ Fix from $1,9502020-10-29 HIGH 8.3 CVE-2020-27653 Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof serv… Router Manager 1.2.4-8081+ Fix from $1,9502020-10-29 MEDIUM 6.1 CVE-2020-27658 Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easi… Router Manager 1.2.4-8081+ Fix from $1,6002020-10-29 MEDIUM 5.9 CVE-2020-27657 Cleartext transmission of sensitive information vulnerability in DDNS in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle att… Router Manager 1.2.4-8081+ Fix from $1,6002020-10-29 CRITICAL 9.0 CVE-2020-27648 Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle a… Diskstation Manager 6.2.3-25426 / 6.2.3-25426-2+ Fix from $2,3002020-10-29 CRITICAL 9.0 CVE-2020-27649 Improper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers… Router Manager 1.2.4-8081+ Fix from $2,3002020-10-29 HIGH 8.1 CVE-2020-27651 Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for re… Router Manager 1.2.4-8081+ Fix from $1,9502020-10-29 HIGH 7.5 CVE-2019-11823 CRLF injection vulnerability in Network Center in Synology Router Manager (SRM) before 1.2.3-8017-2 allows remote attackers to cause a denial of serv… Router Manager 1.2.3-8017-2+ Fix from $1,9502020-05-04 HIGH 8.8 CVE-2019-9501 The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a data length larger than 32 byte… Router Manager No fix yet Fix from $1,9502020-02-03 HIGH 8.8 CVE-2019-9502 The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. If the vendor information element data length is larger than 164 bytes, a heap b… Router Manager Mitigation only Fix from $1,9502020-02-03 CRITICAL 9.8 CVE-2019-11821 SQL injection vulnerability in synophoto_csPhotoDB.php in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to ex… Photo Station 6.3-2977 / 6.8.11-3489+ Fix from $2,3002019-06-30 CRITICAL 9.8 CVE-2019-11829 OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar before 2.3.1-0617 allows remote attackers to execute arbitrar… Calendar 2.3.1-0617+ Fix from $2,3002019-06-30 HIGH 8.8 CVE-2019-11826 Relative path traversal vulnerability in SYNO.PhotoTeam.Upload.Item in Synology Moments before 1.3.0-0691 allows remote authenticated users to upload… Moments 1.3.0-0691+ Fix from $1,9502019-06-30 MEDIUM 6.5 CVE-2019-11822 Relative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attack… Photo Station 6.3-2977 / 6.8.11-3489+ Fix from $1,6002019-06-30 MEDIUM 5.4 CVE-2019-11825 Cross-site scripting (XSS) vulnerability in Event Editor in Synology Calendar before 2.3.0-0615 allows remote attackers to inject arbitrary web scrip… Calendar 2.3.0-0615+ Fix from $1,6002019-06-30 MEDIUM 5.4 CVE-2019-11827 Cross-site scripting (XSS) vulnerability in SYNO.NoteStation.Shard in Synology Note Station before 2.5.3-0863 allows remote attackers to inject arbit… Note Station 2.5.3-0863+ Fix from $1,6002019-06-30 MEDIUM 5.4 CVE-2019-11828 Cross-site scripting (XSS) vulnerability in Chart in Synology Office before 3.1.4-2771 allows remote authenticated users to inject arbitrary web scri… Office 3.1.4-2771+ Fix from $1,6002019-06-30 MEDIUM 5.5 CVE-2019-11820 Information exposure through process environment vulnerability in Synology Calendar before 2.3.3-0620 allows local users to obtain credentials via cm… Calendar 2.3.3-0620+ Fix from $1,6002019-05-09 HIGH 8.8 CVE-2018-13284 Command injection vulnerability in ftpd in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to execute arbitra… Diskstation Manager 5.2-5967-8 / 6.0.3-8754-8+ Fix from $1,9502019-04-01 HIGH 8.8 CVE-2018-13285 Command injection vulnerability in ftpd in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users to execute arbitrary O… Router Manager 1.1.7-6941-1+ Fix from $1,9502019-04-01