Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.1
CVE-2018-13298
Channel accessible by non-endpoint vulnerability in privacy page in Synology Android Moments before 1.2.3-199 allows man-in-the-middle attackers to e…
Moments
1.2.3-199+
HIGH 7.5
CVE-2018-13296
Uncontrolled resource consumption vulnerability in TLS configuration in Synology MailPlus Server before 2.0.5-0606 allows remote attackers to conduct…
Mailplus Server
2.0.5-0606+
HIGH 7.4
CVE-2018-13283
Lack of administrator control over security vulnerability in client.cgi in Synology SSL VPN Client before 1.2.5-0226 allows remote attackers to condu…
Ssl Vpn Client
1.2.5-0226+
MEDIUM 6.5
CVE-2018-13286
Incorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated use…
Diskstation Manager
5.2-5967-8 / 6.0.3-8754-8+
MEDIUM 6.5
CVE-2018-13287
Incorrect default permissions vulnerability in synouser.conf in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users t…
Router Manager
1.1.7-6941-1+
MEDIUM 6.5
CVE-2018-13294
Information exposure vulnerability in SYNO.Personal.Profile in Synology Application Service before 1.5.4-0320 allows remote authenticated users to ob…
Application Service
1.5.4-0320+
MEDIUM 6.5
CVE-2018-13295
Information exposure vulnerability in SYNO.Personal.Application.Info in Synology Application Service before 1.5.4-0320 allows remote authenticated us…
Application Service
1.5.4-0320+
MEDIUM 6.5
CVE-2018-13299
Relative path traversal vulnerability in Attachment Uploader in Synology Calendar before 2.2.2-0532 allows remote authenticated users to upload arbit…
Calendar
2.2.2-0532+
MEDIUM 6.1
CVE-2017-16775
Improper restriction of rendered UI layers or frames vulnerability in SSOOauth.cgi in Synology SSO Server before 2.1.3-0129 allows remote attackers t…
Sso Server
2.1.3-0129+
MEDIUM 6.1
CVE-2018-8913
Missing custom error page vulnerability in Synology Web Station before 2.1.3-0139 allows remote attackers to conduct phishing attacks via a crafted U…
Web Station
2.1.3-0139+
MEDIUM 5.4
CVE-2017-16774
Cross-site scripting (XSS) vulnerability in SYNO.Core.PersonalNotification.Event in Synology DiskStation Manager (DSM) before 6.1.4-15217-3 allows re…
Diskstation Manager
6.1.4-15217-3+
MEDIUM 5.4
CVE-2018-13293
Cross-site scripting (XSS) vulnerability in Control Panel SSO Settings in Synology DiskStation Manager (DSM) before 6.2.1-23824 allows remote authent…
Diskstation Manager
6.2.1-23824+
MEDIUM 5.3
CVE-2018-13288
Information exposure vulnerability in SYNO.FolderSharing.List in Synology File Station before 1.2.3-0252 and before 1.1.5-0125 allows remote attacker…
File Station
1.1.5-0125 / 1.2.2-0250+
MEDIUM 5.3
CVE-2018-13289
Information exposure vulnerability in SYNO.FolderSharing.List in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote attackers to obtain …
Router Manager
1.1.7-6941-2+
MEDIUM 5.3
CVE-2018-13297
Information exposure vulnerability in SYNO.SynologyDrive.Files in Synology Drive before 1.1.2-10562 allows remote attackers to obtain sensitive syste…
Drive Server
1.1.2-10562+
CRITICAL 9.8
CVE-2018-8919
Information exposure vulnerability in SYNO.Core.Desktop.SessionData in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers …
Diskstation Manager
6.1.6-15266+
HIGH 7.2
CVE-2018-8920
Improper neutralization of escape vulnerability in Log Exporter in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to i…
Diskstation Manager
6.1.6-15266+
MEDIUM 5.4
CVE-2018-8917
Cross-site scripting (XSS) vulnerability in info.cgi in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to inject arbit…
Diskstation Manager
6.1.6-15266+
MEDIUM 5.4
CVE-2018-8918
Cross-site scripting (XSS) vulnerability in info.cgi in Synology Router Manager (SRM) before 1.1.7-6941 allows remote attackers to inject arbitrary w…
Router Manager
1.1.7-6941+
MEDIUM 6.3
CVE-2018-13282
Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attackers to hijack web sessions v…
Photo Station
6.3-2976 / 6.8.7-3481+
MEDIUM 5.9
CVE-2018-13280
Use of insufficiently random values vulnerability in SYNO.Encryption.GenRandomKey in Synology DiskStation Manager (DSM) before 6.2-23739 allows man-i…
Diskstation Manager
6.2-23739+
CRITICAL 9.8
CVE-2016-6554
Synology NAS servers DS107, firmware version 3.1-1639 and prior, and DS116, DS213, firmware versions prior to 5.2-5644-1, use non-random default cred…
Ds107 Firmware
after 5.2-5644-1
HIGH 8.1
CVE-2018-8929
Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows …
Ssl Vpn Client
1.2.4-0224+
HIGH 8.8
CVE-2017-16773
Improper authorization vulnerability in Highlight Preview in Synology Universal Search before 1.0.5-0135 allows remote authenticated users to bypass …
Universal Search
1.0.5-0135+
MEDIUM 5.4
CVE-2018-8928
Cross-site scripting (XSS) vulnerability in Address Book Editor in Synology CardDAV Server before 6.0.8-0086 allows remote authenticated users to inj…
Carddav Server
6.0.8-0086+
MEDIUM 6.5
CVE-2018-8927
Improper authorization vulnerability in SYNO.Cal.Event in Calendar before 2.1.2-0511 allows remote authenticated users to create arbitrary events via…
Calendar
2.1.2-0511+
HIGH 8.8
CVE-2018-8916
Unverified password change vulnerability in Change Password in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users …
Diskstation Manager
6.2-23739+
HIGH 8.8
CVE-2018-8925
Cross-site request forgery (CSRF) vulnerability in admin/user.php in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote attac…
Photo Station
6.3-2975 / 6.8.5-3471+
HIGH 8.8
CVE-2018-8926
Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote authe…
Photo Station
6.8.5-3471+
HIGH 7.2
CVE-2017-12075
Command injection vulnerability in EZ-Internet in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to execute ar…
Diskstation Manager
6.2-23739+