← Back

Synology

synology

346 CVEs • 98 products

Products (98)

Click to collapse
Toggle
Photo Station
photo_station
Skynas
skynas
Calendar
calendar
Video Station
video_station
Drive Server
drive_server
Media Server
media_server
Drive Client
drive_client
Beedrive
beedrive
Note Station
note_station
Dns Server
dns_server
Audio Station
audio_station
Radius Server
radius_server
Beestation Os
beestation_os
Chat
chat
Office
office
File Station
file_station
Dsm
dsm
Assistant
assistant
Sso Server
sso_server
Moments
moments
Safeaccess
safeaccess
Ds Photo+
ds_photo+
Ds File
ds_file
Ds Audio
ds_audio
Cloud Station
cloud_station
Vs960hd
vs960hd
Ds107 Firmware
ds107_firmware
Ds213 Firmware
ds213_firmware
Ds116 Firmware
ds116_firmware
Web Station
web_station
Docker
docker
Mail Station
mail_station
Webdav Server
webdav_server
Usb Copy
usb_copy
Photos
photos
Beephotos
beephotos
Mail Server
mail_server
Presto Client
presto_client
Contacts
contacts
Safe Access
safe_access
Vs360hd
vs360hd
Ds107
ds107
Ds213
ds213
Ds116
ds116
Uc3200
uc3200
Ds3622xs+
ds3622xs+
Fs3410
fs3410
Hd6500
hd6500
Bc500
bc500
Tc500
tc500
Cc400w
cc400w

CVEs (346)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Synology
1Sso Server
Nov 21, 2024
Apr 1, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Improper restriction of rendered UI layers or frames vulnerability in SSOOauth.cgi in Synology SSO Server before 2.1.3-0129 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
1Synology
1Diskstation Manager
Jan 14, 2025
Apr 1, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in SYNO.Core.PersonalNotification.Event in Synology DiskStation Manager (DSM) before 6.1.4-15217-3 allows remote authenticated users to inject arbitrary web script or HTML via the...Show more
Cross-site scripting (XSS) vulnerability in SYNO.Core.PersonalNotification.Event in Synology DiskStation Manager (DSM) before 6.1.4-15217-3 allows remote authenticated users to inject arbitrary web script or HTML via the package parameter.Show less
1Synology
1Diskstation Manager
Jan 14, 2025
Dec 24, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Improper neutralization of escape vulnerability in Log Exporter in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to inject arbitrary content to have an unspecified impact by exporting an a...Show more
Improper neutralization of escape vulnerability in Log Exporter in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to inject arbitrary content to have an unspecified impact by exporting an archive in CSV format.Show less
1Synology
1Diskstation Manager
Jan 14, 2025
Dec 24, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Information exposure vulnerability in SYNO.Core.Desktop.SessionData in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to steal credentials via unspecified vectors.
1Synology
1Diskstation Manager
Jan 14, 2025
Dec 24, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in info.cgi in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to inject arbitrary web script or HTML via the host parameter.
1Synology
1Router Manager
Nov 21, 2024
Dec 24, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in info.cgi in Synology Router Manager (SRM) before 1.1.7-6941 allows remote attackers to inject arbitrary web script or HTML via the host parameter.
3Debian
NetatalkSynology
6Debian Linux
Diskstation ManagerNetatalk+3 more
Feb 13, 2026
Dec 20, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to a...Show more
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.Show less
1Synology
1Photo Station
Nov 21, 2024
Oct 31, 2018
N/A· v4
6.3 MEDIUM· v3
6.8 MEDIUM· v2
Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
1Synology
3Diskstation Manager
SkynasVs960hd
Jan 14, 2025
Oct 31, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remote authenticated users to determine the existence and obtain the metadata of arbitrary files via the...Show more
Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remote authenticated users to determine the existence and obtain the metadata of arbitrary files via the file_path parameter.Show less
1Synology
1Diskstation Manager
Jan 14, 2025
Jul 30, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Use of insufficiently random values vulnerability in SYNO.Encryption.GenRandomKey in Synology DiskStation Manager (DSM) before 6.2-23739 allows man-in-the-middle attackers to compromise non-HTTPS sessions via unspecified...Show more
Use of insufficiently random values vulnerability in SYNO.Encryption.GenRandomKey in Synology DiskStation Manager (DSM) before 6.2-23739 allows man-in-the-middle attackers to compromise non-HTTPS sessions via unspecified vectors.Show less
1Synology
3Ds107 Firmware
Ds116 FirmwareDs213 Firmware
Nov 21, 2024
Jul 13, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Synology NAS servers DS107, firmware version 3.1-1639 and prior, and DS116, DS213, firmware versions prior to 5.2-5644-1, use non-random default credentials of: guest:(blank) and admin:(blank) . A remote network attacker...Show more
Synology NAS servers DS107, firmware version 3.1-1639 and prior, and DS116, DS213, firmware versions prior to 5.2-5644-1, use non-random default credentials of: guest:(blank) and admin:(blank) . A remote network attacker can gain privileged access to a vulnerable device.Show less
1Synology
1Ssl Vpn Client
Nov 21, 2024
Jul 6, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows remote attackers to conduct man-in-the-middle attacks via a crafted pay...Show more
Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows remote attackers to conduct man-in-the-middle attacks via a crafted payload.Show less
1Synology
1Carddav Server
Nov 21, 2024
Jul 5, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Address Book Editor in Synology CardDAV Server before 6.0.8-0086 allows remote authenticated users to inject arbitrary web script or HTML via the (1) family_name, (2) given_nam...Show more
Cross-site scripting (XSS) vulnerability in Address Book Editor in Synology CardDAV Server before 6.0.8-0086 allows remote authenticated users to inject arbitrary web script or HTML via the (1) family_name, (2) given_name, or (3) additional_name parameter.Show less
1Synology
1Universal Search
Nov 21, 2024
Jul 5, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improper authorization vulnerability in Highlight Preview in Synology Universal Search before 1.0.5-0135 allows remote authenticated users to bypass permission checks for directories in POSIX mode.
1Synology
1Calendar
Nov 21, 2024
Jun 14, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper authorization vulnerability in SYNO.Cal.Event in Calendar before 2.1.2-0511 allows remote authenticated users to create arbitrary events via the (1) cal_id or (2) original_cal_id parameter.
1Synology
1Photo Station
Nov 21, 2024
Jun 8, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote authenticated users to conduct privilege escalation attacks via the fullname...Show more
Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote authenticated users to conduct privilege escalation attacks via the fullname parameter.Show less
1Synology
1Photo Station
Nov 21, 2024
Jun 8, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in admin/user.php in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote attackers to hijack the authentication of administrators via the (1) usernam...Show more
Cross-site request forgery (CSRF) vulnerability in admin/user.php in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote attackers to hijack the authentication of administrators via the (1) username, (2) password, (3) admin, (4) action, (5) uid, or (6) modify_admin parameter.Show less
1Synology
1Diskstation Manager
Jan 14, 2025
Jun 8, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Unverified password change vulnerability in Change Password in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to reset password without verification.
1Synology
1Router Manager
Nov 21, 2024
Jun 8, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Command injection vulnerability in EZ-Internet in Synology Router Manager (SRM) before 1.1.6-6931 allows remote authenticated users to execute arbitrary command via the username parameter.
1Synology
1Diskstation Manager
Jan 14, 2025
Jun 8, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Command injection vulnerability in EZ-Internet in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to execute arbitrary command via the username parameter.