← Back

Synology

synology

351 CVEs • 102 products

Products (102)

Click to collapse
Toggle
Photo Station
photo_station
Skynas
skynas
Calendar
calendar
Video Station
video_station
Drive Server
drive_server
Media Server
media_server
Drive Client
drive_client
Beedrive
beedrive
Note Station
note_station
Dns Server
dns_server
Audio Station
audio_station
Radius Server
radius_server
Beestation Os
beestation_os
Chat
chat
Office
office
File Station
file_station
Dsm
dsm
Assistant
assistant
Sso Server
sso_server
Moments
moments
Safeaccess
safeaccess
Hyper Backup
hyper_backup
Ds Photo+
ds_photo+
Ds File
ds_file
Ds Audio
ds_audio
Cloud Station
cloud_station
Vs960hd
vs960hd
Ds107 Firmware
ds107_firmware
Ds213 Firmware
ds213_firmware
Ds116 Firmware
ds116_firmware
Web Station
web_station
Docker
docker
Mail Station
mail_station
Webdav Server
webdav_server
Usb Copy
usb_copy
Photos
photos
Beephotos
beephotos
Mail Server
mail_server
Presto Client
presto_client
Contacts
contacts
Safe Access
safe_access
Vs360hd
vs360hd
Ds107
ds107
Ds213
ds213
Ds116
ds116
Uc3200
uc3200
Ds3622xs+
ds3622xs+
Fs3410
fs3410
Hd6500
hd6500
Bc500
bc500

CVEs (351)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Synology
1Surveillance Station
Jun 17, 2026
May 27, 2026
N/A· v4
2.7 LOW· v3
N/A· v2
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated...Show more
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors.Show less
1Synology
1Beedrive
Jun 17, 2026
May 27, 2026
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to conduct denial-of-service attacks via unspecified vect...Show more
Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to conduct denial-of-service attacks via unspecified vectors.Show less
1Synology
1Beedrive
Jun 17, 2026
May 27, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to execute arbitrary code via unspecified vectors.
1Synology
1Ssl Vpn Client
Jun 17, 2026
Apr 10, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN c...Show more
A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined with user interaction.Show less
1Synology
1Ssl Vpn Client
Jun 17, 2026
Apr 10, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to...Show more
A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interface. By leveraging user interaction with a crafted web page, attackers may retrieve sensitive files such as configuration files, certificates, and logs, leading to information disclosure.Show less
1Synology
1Presto Client
Jun 17, 2026
Feb 24, 2026
N/A· v4
7.3 HIGH· v3
N/A· v2
An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files and conduct denial-of-service during installation by placing a malicious D...Show more
An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files and conduct denial-of-service during installation by placing a malicious DLL in advance in the same directory as the installer.Show less
1Synology
1Beedrive
Jun 17, 2026
Dec 4, 2025
N/A· v4
5.6 MEDIUM· v3
N/A· v2
Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users to write arbitrary files with non-sensitive information via unspecified vectors.
1Synology
1Beedrive
Jun 17, 2026
Dec 4, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified ve...Show more
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors.Show less
1Synology
1Beedrive
Jun 17, 2026
Dec 4, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitrary files via unspecified vectors.
1Synology
1Beedrive
Jun 17, 2026
Dec 4, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors.
1Synology
1Mail Server
Jun 17, 2026
Dec 4, 2025
N/A· v4
6.3 MEDIUM· v3
N/A· v2
A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical functions.
1Synology
1Router Manager
Jun 17, 2026
Dec 4, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.
1Synology
1Router Manager
Jun 17, 2026
Dec 4, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.
1Synology
1Router Manager
Jun 17, 2026
Dec 4, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.
1Synology
1Router Manager
Jun 17, 2026
Dec 4, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.
1Synology
2Diskstation Manager
Diskstation Manager Unified Controller
Jun 17, 2026
Dec 4, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before 7.1.1-42962-8 and 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC...Show more
Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before 7.1.1-42962-8 and 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote authenticated users to obtain privileges without consent via unspecified vectors.Show less
1Synology
2Diskstation Manager
Diskstation Manager Unified Controller
Jun 17, 2026
Dec 4, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Out-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to conduct...Show more
Out-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to conduct denial-of-service attacks via unspecified vectors.Show less
1Synology
2Diskstation Manager
Diskstation Manager Unified Controller
Jun 17, 2026
Dec 4, 2025
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote atta...Show more
Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code via unspecified vectors.Show less
1Synology
1Router Manager
Jun 17, 2026
Jul 23, 2025
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in NTP Region functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with...Show more
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in NTP Region functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors.Show less
1Synology
1Router Manager
Jun 17, 2026
Jul 23, 2025
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with...Show more
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors.Show less