Vulnerability index

Browse CVEs

280 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2017-12078 Command injection vulnerability in EZ-Internet in Synology Router Manager (SRM) before 1.1.6-6931 allows remote authenticated users to execute arbitr… Router Manager 1.1.6-6931+ Fix from $1,9502018-06-08 MEDIUM 5.4 CVE-2018-8923 Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology File Station before 1.1.4-0122 allows remote authenticated users to inject… File Station 1.1.4-0122+ Fix from $1,6002018-06-05 MEDIUM 5.4 CVE-2018-8924 Cross-site scripting (XSS) vulnerability in Title Tootip in Synology Office before 3.0.3-2143 allows remote authenticated users to inject arbitrary w… Office 3.0.3-2143+ Fix from $1,6002018-06-05 MEDIUM 6.5 CVE-2018-8922 Improper access control vulnerability in Synology Drive before 1.0.2-10275 allows remote authenticated users to access non-shared files or folders vi… Drive Server Mitigation only Fix from $1,6002018-06-01 MEDIUM 5.4 CVE-2018-8921 Cross-site scripting (XSS) vulnerability in File Sharing Notify Toast in Synology Drive before 1.0.2-10275 allows remote authenticated users to injec… Drive Server 1.0.2-10275+ Fix from $1,6002018-06-01 CRITICAL 9.8 CVE-2018-8914 SQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote attackers to execute arbitrary S… Media Server 1.4-2654 / 1.7.6-2842+ Fix from $2,3002018-05-10 MEDIUM 5.4 CVE-2018-8910 Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology Drive before 1.0.1-10253 allows remote authenticated users to inject arbit… Drive Server 1.0.1-10253+ Fix from $1,6002018-05-10 MEDIUM 5.4 CVE-2018-8915 Cross-site scripting (XSS) vulnerability in Notification Center in Synology Calendar before 2.1.1-0502 allows remote authenticated users to inject ar… Calendar 2.1.1-0502+ Fix from $1,6002018-05-10 MEDIUM 5.4 CVE-2018-8911 Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology Note Station before 2.5.1-0844 allows remote authenticated users to inject… Note Station 2.5.1-0844+ Fix from $1,6002018-05-09 MEDIUM 5.4 CVE-2018-8912 Cross-site scripting (XSS) vulnerability in SYNO.NoteStation.Note in Synology Note Station before 2.5.1-0844 allows remote authenticated users to inj… Note Station 2.5.1-0844+ Fix from $1,6002018-05-09 HIGH 8.8 CVE-2017-16772 Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote… Photo Station 6.3-2971 / 6.8.3-3463+ Fix from $1,9502018-03-22 MEDIUM 6.1 CVE-2017-16771 Cross-site scripting (XSS) vulnerability in Log Viewer in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote attackers to inj… Photo Station 6.3-2971 / 6.8.3-3463+ Fix from $1,6002018-03-22 MEDIUM 6.5 CVE-2017-16770 File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.… Surveillance Station 8.1.2-5469+ Fix from $1,6002018-02-27 MEDIUM 5.4 CVE-2017-16767 Cross-site scripting (XSS) vulnerability in User Profile in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to inje… Surveillance Station 8.1.2-5469+ Fix from $1,6002018-02-27 MEDIUM 5.3 CVE-2017-16769 Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from pa… Photo Station Mitigation only Fix from $1,6002018-02-23 MEDIUM 6.5 CVE-2017-15886 Server-side request forgery (SSRF) vulnerability in Link Preview in Synology Chat before 2.0.0-1124 allows remote authenticated users to download arb… Chat 2.0.0-1124+ Fix from $1,6002017-12-28 MEDIUM 5.4 CVE-2017-15892 Multiple cross-site scripting (XSS) vulnerabilities in Slash Command Creator in Synology Chat before 2.0.0-1124 allow remote authenticated users to i… Chat 2.0.0-1124+ Fix from $1,6002017-12-28 MEDIUM 6.5 CVE-2017-16766 An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows loc… Diskstation Manager 6.0.3-8754-6 / 6.1.4-15217+ Fix from $1,6002017-12-22 MEDIUM 5.4 CVE-2017-12072 Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.8.0-3456 allows remote authenticated users to i… Photo Station 6.8.0-3456+ Fix from $1,6002017-12-20 MEDIUM 6.5 CVE-2017-15891 Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authenticated users to modify calend… Calendar 2.0.1-0242+ Fix from $1,6002017-12-08 MEDIUM 6.5 CVE-2017-15893 Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology File Station before 1.1.1-0099 allows remote authenticated users to wri… File Station 1.1.1-0099+ Fix from $1,6002017-12-08 MEDIUM 6.5 CVE-2017-15894 Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology DiskStation Manager (DSM) 6.0.x before 6.0.3-8754-3 and before 5.2-5967… Diskstation Manager 5.2-5967-6 / 6.0.3-8754-3+ Fix from $1,6002017-12-08 MEDIUM 6.5 CVE-2017-15895 Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology Router Manager (SRM) before 1.1.5-6542-4 allows remote authenticated us… Router Manager 1.1.5-6542-4+ Fix from $1,6002017-12-08 HIGH 8.8 CVE-2017-15889EPSS 72% Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arb… Diskstation Manager 5.2-5967-5+ Fix from $1,9502017-12-04 HIGH 7.5 CVE-2017-12079 Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allow… Photo Station 6.3-2970 / 6.8.1-3458+ Fix from $1,9502017-12-04 MEDIUM 5.3 CVE-2017-12080 An information exposure vulnerability in default HTTP configuration file in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remot… Photo Station 6.3-2970 / 6.8.1-3458+ Fix from $1,6002017-12-04 CRITICAL 9.8 CVE-2017-15887 An improper restriction of excessive authentication attempts vulnerability in /principals in Synology CardDAV Server before 6.0.7-0085 allows remote … Carddav Server 6.0.7-0085+ Fix from $2,3002017-11-07 MEDIUM 5.4 CVE-2017-15888 Cross-site scripting (XSS) vulnerability in Custom Internet Radio List in Synology Audio Station before 6.3.0-3260 allows remote authenticated attack… Audio Station 6.3.0-3260+ Fix from $1,6002017-10-30 CRITICAL 9.8 CVE-2017-11161 Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL comma… Photo Station after 6.7.3-3432 Fix from $2,3002017-09-08 MEDIUM 6.5 CVE-2017-11162 Directory traversal vulnerability in synphotoio in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to read ar… Photo Station after 6.7.3-3432 Fix from $1,6002017-09-08