Diskstation Manager Unified Controller
diskstation_manager_unified_controller
Vendor: Synology • 20 CVEs
CVEs (20)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Synology 2Diskstation Manager Diskstation Manager Unified ControllerJun 17, 2026 Dec 4, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before 7.1.1-42962-8 and 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC...Show more |
1Synology 2Diskstation Manager Diskstation Manager Unified ControllerJun 17, 2026 Dec 4, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Out-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to conduct...Show more |
1Synology 2Diskstation Manager Diskstation Manager Unified ControllerJun 17, 2026 Dec 4, 2025 N/A· v4 9.6 CRITICAL· v3 N/A· v2 Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote atta...Show more |
1Synology 3Diskstation Manager Diskstation Manager Unified ControllerRouter ManagerJun 17, 2026 Jun 13, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7.2-64561 allows remote attackers to obtain user credential via unspecified vectors. |
1Synology 3Diskstation Manager Diskstation Manager Unified ControllerRouter ManagerJun 17, 2026 Jun 13, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrat...Show more |
1Synology 2Diskstation Manager Diskstation Manager Unified ControllerJun 17, 2026 Mar 25, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary...Show more |
1Synology 2Diskstation Manager Diskstation Manager Unified ControllerJun 17, 2026 Jun 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to write arbitrary files...Show more |
1Synology 2Diskstation Manager Diskstation Manager Unified ControllerJun 17, 2026 Jun 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Exposure of sensitive information to an unauthorized actor vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to obtain sensitive information via unspecif...Show more |
1Synology 2Diskstation Manager Diskstation Manager Unified ControllerJun 17, 2026 Jun 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file sharing management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remo...Show more |
1Synology 2Diskstation Manager Diskstation Manager Unified ControllerJun 17, 2026 Jun 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Security Advisor report management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3...Show more |
1Synology 2Diskstation Manager Diskstation Manager Unified ControllerJun 17, 2026 Jun 23, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors. |
2Faad2 Project Synology5Diskstation Manager Diskstation Manager Unified ControllerFaad2+2 moreJun 17, 2026 Feb 26, 2021 N/A· v4 7.8 HIGH· v3 6.5 MEDIUM· v2 Stack-based buffer overflow vulnerability in frontend/main.c in faad2 before 2.2.7.1 allow local attackers to execute arbitrary code via filename and pathname options. |
1Synology 4Diskstation Manager Diskstation Manager Unified ControllerSkynas Firmware+1 moreJun 17, 2026 Feb 26, 2021 N/A· v4 9.0 CRITICAL· v3 6.8 MEDIUM· v2 Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary commands via inbound QuickC...Show more |
1Synology 4Diskstation Manager Diskstation Manager Unified ControllerSkynas Firmware+1 moreJun 17, 2026 Feb 26, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to obtain sensitive information via an HTTP sessio...Show more |
1Synology 4Diskstation Manager Diskstation Manager Unified ControllerSkynas Firmware+1 moreJun 17, 2026 Feb 26, 2021 N/A· v4 8.7 HIGH· v3 5.8 MEDIUM· v2 Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to spoof servers via an HTTP session. |
1Synology 4Diskstation Manager Diskstation Manager Unified ControllerSkynas Firmware+1 moreJun 17, 2026 Feb 26, 2021 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Incorrect authorization vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to execute arbitrary code via unspecified vectors. |
1Synology 4Diskstation Manager Diskstation Manager Unified ControllerSkynas Firmware+1 moreJun 17, 2026 Feb 26, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Out-of-bounds write vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary code via syno_finder_site HTTP header. |
1Synology 4Diskstation Manager Diskstation Manager Unified ControllerSkynas Firmware+1 moreJun 17, 2026 Feb 26, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Stack-based buffer overflow vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary code via syno_finder_site HTTP header. |
1Synology 4Diskstation Manager Diskstation Manager Unified ControllerSkynas Firmware+1 moreJun 17, 2026 Feb 26, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Cleartext transmission of sensitive information vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to spoof servers via an HTTP session. |
8Beyondtrust DebianFedoraproject+5 more24Active Iq Unified Manager Cloud BackupCommunications Performance Intelligence Center+21 moreJun 17, 2026 Jan 26, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash...Show more |