← Back

Synology

synology

351 CVEs • 102 products

Products (102)

Click to collapse
Toggle
Photo Station
photo_station
Skynas
skynas
Calendar
calendar
Video Station
video_station
Drive Server
drive_server
Media Server
media_server
Drive Client
drive_client
Beedrive
beedrive
Note Station
note_station
Dns Server
dns_server
Audio Station
audio_station
Radius Server
radius_server
Beestation Os
beestation_os
Chat
chat
Office
office
File Station
file_station
Dsm
dsm
Assistant
assistant
Sso Server
sso_server
Moments
moments
Safeaccess
safeaccess
Hyper Backup
hyper_backup
Ds Photo+
ds_photo+
Ds File
ds_file
Ds Audio
ds_audio
Cloud Station
cloud_station
Vs960hd
vs960hd
Ds107 Firmware
ds107_firmware
Ds213 Firmware
ds213_firmware
Ds116 Firmware
ds116_firmware
Web Station
web_station
Docker
docker
Mail Station
mail_station
Webdav Server
webdav_server
Usb Copy
usb_copy
Photos
photos
Beephotos
beephotos
Mail Server
mail_server
Presto Client
presto_client
Contacts
contacts
Safe Access
safe_access
Vs360hd
vs360hd
Ds107
ds107
Ds213
ds213
Ds116
ds116
Uc3200
uc3200
Ds3622xs+
ds3622xs+
Fs3410
fs3410
Hd6500
hd6500
Bc500
bc500

CVEs (351)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Synology
1Surveillance Station
Nov 21, 2024
Feb 27, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to obtain other user's sensiti...Show more
File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to obtain other user's sensitive files via the filename parameter.Show less
1Synology
1Surveillance Station
Nov 21, 2024
Feb 27, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in User Profile in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to inject arbitrary web script or HTML via the userDesc parameter.
1Synology
1Photo Station
Nov 21, 2024
Feb 23, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from password-protected photographs via the map viewer mode.
13Arm
CanonicalDebian+10 more
308Atom C
Atom EAtom X3+305 more
May 28, 2026
Jan 4, 2018
N/A· v4
5.6 MEDIUM· v3
4.7 MEDIUM· v2
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
1Synology
1Chat
May 13, 2026
Dec 28, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in Slash Command Creator in Synology Chat before 2.0.0-1124 allow remote authenticated users to inject arbitrary web script or HTML via (1) COMMAND, (2) COMMANDS INSTRU...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Slash Command Creator in Synology Chat before 2.0.0-1124 allow remote authenticated users to inject arbitrary web script or HTML via (1) COMMAND, (2) COMMANDS INSTRUCTION, or (3) DESCRIPTION parameter.Show less
1Synology
1Chat
May 13, 2026
Dec 28, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Server-side request forgery (SSRF) vulnerability in Link Preview in Synology Chat before 2.0.0-1124 allows remote authenticated users to download arbitrary local files via a crafted URI.
1Synology
1Mailplus Server
May 13, 2026
Dec 27, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in User Policy editor in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary HTML via the name parameter.
1Synology
1Diskstation Manager
May 13, 2026
Dec 22, 2017
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows local users to inject arbitrary web script or HTML via the -fn option.
1Synology
1Photo Station
May 13, 2026
Dec 20, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.8.0-3456 allows remote authenticated users to inject arbitrary web scripts or HTML via the id parameter.
1Synology
1Mailplus Server
May 13, 2026
Dec 15, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Disclaimer in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary web script or HTML via the NAME parameter.
1Synology
1Router Manager
May 13, 2026
Dec 8, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology Router Manager (SRM) before 1.1.5-6542-4 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.
1Synology
1Diskstation Manager
May 13, 2026
Dec 8, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology DiskStation Manager (DSM) 6.0.x before 6.0.3-8754-3 and before 5.2-5967-6 allows remote authenticated users to write arbitrary files via the d...Show more
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology DiskStation Manager (DSM) 6.0.x before 6.0.3-8754-3 and before 5.2-5967-6 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.Show less
1Synology
1File Station
May 13, 2026
Dec 8, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology File Station before 1.1.1-0099 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.
1Synology
1Calendar
May 13, 2026
Dec 8, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authenticated users to modify calendar event via unspecified vectors.
1Synology
1Diskstation Manager
May 13, 2026
Dec 4, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field.
1Synology
1Photo Station
May 13, 2026
Dec 4, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An information exposure vulnerability in default HTTP configuration file in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain sensitive system information via .htaccess file.
1Synology
1Photo Station
May 13, 2026
Dec 4, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain arbitrary files via prog_id field.
1Synology
1Carddav Server
May 13, 2026
Nov 7, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An improper restriction of excessive authentication attempts vulnerability in /principals in Synology CardDAV Server before 6.0.7-0085 allows remote attackers to obtain user credentials via a brute-force attack.
1Synology
1Audio Station
May 13, 2026
Oct 30, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Custom Internet Radio List in Synology Audio Station before 6.3.0-3260 allows remote authenticated attackers to inject arbitrary web script or HTML via the NAME parameter.
12Arista
ArubanetworksCanonical+9 more
21Arubaos
Debian LinuxDiskstation Manager+18 more
May 13, 2026
Oct 4, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.