Skip to main content

Vendor archive

synology CVEs

Beta · best-effort

349 CVEs tagged to vendor synology39 Critical, 120 High, 183 Medium, 7 Low, 0 Unrated.

CVE-2024-0854

Published Jan 24, 2024

URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7, 7.1.1-42962-7…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5748

Published Nov 7, 2023

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology SSL VPN Client before 1.4.7-0687 allows local users to conduct de…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-41741

Published Aug 31, 2023

Exposure of sensitive information to an unauthorized actor vulnerability in cgi component in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote attackers to obtain se…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41740

Published Aug 31, 2023

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote at…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41739

Published Aug 31, 2023

Uncontrolled resource consumption vulnerability in File Functionality in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote authenticated users to conduct denial-of-s…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41738

Published Aug 31, 2023

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Directory Domain Functionality in Synology Router Manager (SRM) before…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32956

Published May 16, 2023

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-32955

Published May 16, 2023

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DHCP Client Functionality in Synology Router Manager (SRM) before 1.2.5…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0077

Published Jan 5, 2023

Integer overflow or wraparound vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote attackers to overflow buffers via…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43932

Published Jan 5, 2023

Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-822…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43931

Published Jan 3, 2023

Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server before 1.4.3-0534 and 1.4.4-0635 allows remote attackers to execute arbitrary command…

CVSS 10.0 · Critical
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2022-43749

Published Oct 26, 2022

Improper privilege management vulnerability in summary report management in Synology Presto File Server before 2.1.2-1601 allows remote authenticated users to bypass security cons…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43748

Published Oct 26, 2022

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file operation management in Synology Presto File Server before 2.1.2-1601 allows r…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-27623

Published Oct 25, 2022

Missing authentication for critical function vulnerability in iSCSI management functionality in Synology DiskStation Manager (DSM) before 7.1-42661 allows remote attackers to read…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27622

Published Oct 25, 2022

Server-Side Request Forgery (SSRF) vulnerability in Package Center functionality in Synology DiskStation Manager (DSM) before 7.1-42661 allows remote authenticated users to access…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-27619

Published Aug 3, 2022

Cleartext transmission of sensitive information vulnerability in authentication management in Synology Note Station Client before 2.2.2-609 allows man-in-the-middle attackers to o…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 101-125 of 349 CVEsPage 5 of 14