Synology
synology
351 CVEs • 102 products
Products (102)
Click to collapseToggle
Products (102)
Click to collapse
CVEs (351)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Synology 4Diskstation Manager Diskstation Manager Unified ControllerSkynas Firmware+1 moreJun 17, 2026 Feb 26, 2021 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Incorrect authorization vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to execute arbitrary code via unspecified vectors. |
1Synology 4Diskstation Manager Diskstation Manager Unified ControllerSkynas Firmware+1 moreJun 17, 2026 Feb 26, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Out-of-bounds write vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary code via syno_finder_site HTTP header. |
1Synology 4Diskstation Manager Diskstation Manager Unified ControllerSkynas Firmware+1 moreJun 17, 2026 Feb 26, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Stack-based buffer overflow vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary code via syno_finder_site HTTP header. |
1Synology 4Diskstation Manager Diskstation Manager Unified ControllerSkynas Firmware+1 moreJun 17, 2026 Feb 26, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Cleartext transmission of sensitive information vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to spoof servers via an HTTP session. |
8Beyondtrust DebianFedoraproject+5 more24Active Iq Unified Manager Cloud BackupCommunications Performance Intelligence Center+21 moreJun 17, 2026 Jan 26, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash...Show more |
SQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute arbitrary SQL commands via the domain parameter. |
Multiple cross-site scripting (XSS) vulnerabilities in Synology SafeAccess before 1.2.3-0234 allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) profile parameter. |
Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via...Show more |
Cleartext transmission of sensitive information vulnerability in DDNS in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via unspecifi...Show more |
Cleartext transmission of sensitive information vulnerability in DDNS in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via u...Show more |
Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via inbound QuickConnect traffic. |
Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands via port (1) 7786/tcp or (2) 7787/tcp. |
1Synology 2Diskstation Manager Router ManagerJun 17, 2026 Oct 29, 2020 N/A· v4 8.3 HIGH· v3 5.1 MEDIUM· v2 Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors. |
1Synology 2Diskstation Manager Skynas FirmwareJun 17, 2026 Oct 29, 2020 N/A· v4 8.3 HIGH· v3 5.1 MEDIUM· v2 Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors. |
Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission...Show more |
1Synology 2Diskstation Manager Skynas FirmwareJun 17, 2026 Oct 29, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its trans...Show more |
Improper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certif...Show more |
1Synology 2Diskstation Manager Skynas FirmwareJun 17, 2026 Oct 29, 2020 N/A· v4 9.0 CRITICAL· v3 6.8 MEDIUM· v2 Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafte...Show more |
7Canonical DebianFedoraproject+4 more7Bind Debian LinuxDns Server+4 moreJun 17, 2026 Aug 21, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query p...Show more |
8Canonical DebianFedoraproject+5 more8Bind Communications Diameter Signaling RouterDebian Linux+5 moreJun 17, 2026 Aug 21, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the serve...Show more |