← Back

Synology

synology

346 CVEs • 98 products

Products (98)

Click to collapse
Toggle
Photo Station
photo_station
Skynas
skynas
Calendar
calendar
Video Station
video_station
Drive Server
drive_server
Media Server
media_server
Drive Client
drive_client
Beedrive
beedrive
Note Station
note_station
Dns Server
dns_server
Audio Station
audio_station
Radius Server
radius_server
Beestation Os
beestation_os
Chat
chat
Office
office
File Station
file_station
Dsm
dsm
Assistant
assistant
Sso Server
sso_server
Moments
moments
Safeaccess
safeaccess
Ds Photo+
ds_photo+
Ds File
ds_file
Ds Audio
ds_audio
Cloud Station
cloud_station
Vs960hd
vs960hd
Ds107 Firmware
ds107_firmware
Ds213 Firmware
ds213_firmware
Ds116 Firmware
ds116_firmware
Web Station
web_station
Docker
docker
Mail Station
mail_station
Webdav Server
webdav_server
Usb Copy
usb_copy
Photos
photos
Beephotos
beephotos
Mail Server
mail_server
Presto Client
presto_client
Contacts
contacts
Safe Access
safe_access
Vs360hd
vs360hd
Ds107
ds107
Ds213
ds213
Ds116
ds116
Uc3200
uc3200
Ds3622xs+
ds3622xs+
Fs3410
fs3410
Hd6500
hd6500
Bc500
bc500
Tc500
tc500
Cc400w
cc400w

CVEs (346)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Synology
1Chat
May 13, 2026
Dec 28, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Server-side request forgery (SSRF) vulnerability in Link Preview in Synology Chat before 2.0.0-1124 allows remote authenticated users to download arbitrary local files via a crafted URI.
1Synology
1Mailplus Server
May 13, 2026
Dec 27, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in User Policy editor in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary HTML via the name parameter.
1Synology
1Diskstation Manager
May 13, 2026
Dec 22, 2017
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows local users to inject arbitrary web script or HTML via the -fn option.
1Synology
1Photo Station
May 13, 2026
Dec 20, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.8.0-3456 allows remote authenticated users to inject arbitrary web scripts or HTML via the id parameter.
1Synology
1Mailplus Server
May 13, 2026
Dec 15, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Disclaimer in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary web script or HTML via the NAME parameter.
1Synology
1Router Manager
May 13, 2026
Dec 8, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology Router Manager (SRM) before 1.1.5-6542-4 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.
1Synology
1Diskstation Manager
May 13, 2026
Dec 8, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology DiskStation Manager (DSM) 6.0.x before 6.0.3-8754-3 and before 5.2-5967-6 allows remote authenticated users to write arbitrary files via the d...Show more
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology DiskStation Manager (DSM) 6.0.x before 6.0.3-8754-3 and before 5.2-5967-6 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.Show less
1Synology
1File Station
May 13, 2026
Dec 8, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology File Station before 1.1.1-0099 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.
1Synology
1Calendar
May 13, 2026
Dec 8, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authenticated users to modify calendar event via unspecified vectors.
1Synology
1Diskstation Manager
May 13, 2026
Dec 4, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field.
1Synology
1Photo Station
May 13, 2026
Dec 4, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An information exposure vulnerability in default HTTP configuration file in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain sensitive system information via .htaccess file.
1Synology
1Photo Station
May 13, 2026
Dec 4, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain arbitrary files via prog_id field.
1Synology
1Carddav Server
May 13, 2026
Nov 7, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An improper restriction of excessive authentication attempts vulnerability in /principals in Synology CardDAV Server before 6.0.7-0085 allows remote attackers to obtain user credentials via a brute-force attack.
1Synology
1Audio Station
May 13, 2026
Oct 30, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Custom Internet Radio List in Synology Audio Station before 6.3.0-3260 allows remote authenticated attackers to inject arbitrary web script or HTML via the NAME parameter.
12Arista
ArubanetworksCanonical+9 more
21Arubaos
Debian LinuxDiskstation Manager+18 more
May 13, 2026
Oct 4, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
1Synology
1Photo Station
May 13, 2026
Sep 8, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to download arbitrary local files via the url parameter.
1Synology
1Photo Station
May 13, 2026
Sep 8, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in synphotoio in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to read arbitrary files via unspecified vectors.
1Synology
1Photo Station
May 13, 2026
Sep 8, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to label.php; or (2) type paramete...Show more
Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to label.php; or (2) type parameter to synotheme.php.Show less
1Synology
1Cloud Station Drive
May 13, 2026
Aug 31, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Multiple untrusted search path vulnerabilities in the installer in Synology Cloud Station Drive before 4.2.5-4396 on Windows allow local attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan...Show more
Multiple untrusted search path vulnerabilities in the installer in Synology Cloud Station Drive before 4.2.5-4396 on Windows allow local attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current working directory.Show less
1Synology
1Cloud Station Backup
May 13, 2026
Aug 30, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Multiple untrusted search path vulnerabilities in the installer in Synology Cloud Station Backup before 4.2.5-4396 on Windows allow local attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan...Show more
Multiple untrusted search path vulnerabilities in the installer in Synology Cloud Station Backup before 4.2.5-4396 on Windows allow local attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current working directory.Show less