Vulnerability index

Browse CVEs

19 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Active Backup For Business HIGH 8.6
CVE-2025-30028

A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.

Mitigation only
Fix from $1,950 2026-05-27
Active Backup For Microsoft 365 MEDIUM 6.5
CVE-2025-4679

A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive information via unspecified vec…

Mitigation only
Fix from $1,600 2025-05-16
Router Manager HIGH 8.8
CVE-2019-9501

The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a data length larger than 32 byte…

No fix yet
Fix from $1,950 2020-02-03
Router Manager HIGH 8.8
CVE-2019-9502

The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. If the vendor information element data length is larger than 164 bytes, a heap b…

Mitigation only
Fix from $1,950 2020-02-03
Drive Server MEDIUM 6.5
CVE-2018-8922

Improper access control vulnerability in Synology Drive before 1.0.2-10275 allows remote authenticated users to access non-shared files or folders vi…

Mitigation only
Fix from $1,600 2018-06-01
Photo Station MEDIUM 5.3
CVE-2017-16769

Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from pa…

Mitigation only
Fix from $1,600 2018-02-23
Office HIGH 7.8
CVE-2017-11150

Command injection vulnerability in Document.php in Synology Office 2.2.0-1502 and 2.2.1-1506 allows remote authenticated users to execute arbitrary c…

Mitigation only
Fix from $1,950 2017-08-14
Download Station HIGH 7.8
CVE-2017-11156

Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsearch directory, which allows re…

Mitigation only
Fix from $1,950 2017-08-14
Download Station MEDIUM 6.5
CVE-2017-11149

Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows re…

Mitigation only
Fix from $1,600 2017-08-14
Audio Station MEDIUM 5.4
CVE-2015-9104

Cross-site scripting (XSS) vulnerabilities in Synology Audio Station 5.1 before 5.1-2550 and 5.4 before 5.4-2857 allows remote authenticated attacker…

Mitigation only
Fix from $1,600 2017-06-30
Video Station MEDIUM 5.4
CVE-2015-9105

Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, and 1.6 before 1.6-0847 allow…

Mitigation only
Fix from $1,600 2017-06-30
Photo Station HIGH 7.8
CVE-2017-9552

A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology …

Mitigation only
Fix from $1,950 2017-06-13
Cloud Station MEDIUM 6.8
CVE-2015-2851

client_chown in the sync client in Synology Cloud Station 1.1-2291 through 3.1-3320 on OS X allows local users to change the ownership of arbitrary f…

Mitigation only
Fix from $1,600 2015-05-30
Ds Audio MEDIUM 5.4
CVE-2014-6868

The DS audio (aka com.synology.DSaudio) application 3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-midd…

Mitigation only
Fix from $1,600 2014-10-02
Ds File MEDIUM 5.4
CVE-2014-6848

The DS file (aka com.synology.DSfile) application 4.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-midd…

Mitigation only
Fix from $1,600 2014-09-30
Ds Photo\+ MEDIUM 5.4
CVE-2014-6836

The DS photo+ (aka com.synology.dsphoto) application 3.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-mid…

Mitigation only
Fix from $1,600 2014-09-30
Diskstation Manager HIGH 7.8
CVE-2014-2264

The OpenVPN module in Synology DiskStation Manager (DSM) 4.3-3810 update 1 has a hardcoded root password of synopass, which makes it easier for remot…

Mitigation only
Fix from $1,950 2014-03-02
Diskstation Manager HIGH 10.0
CVE-2013-6955EPSS 85%

webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 allows remo…

Mitigation only
Fix from $1,950 2014-01-09
Diskstation Manager HIGH 7.5
CVE-2013-6987EPSS 15%

Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before 4.3-3810 Update 3 allow remot…

No fix yet
Fix from $1,950 2013-12-31