← Back

Synology

synology

346 CVEs • 98 products

Products (98)

Click to collapse
Toggle
Photo Station
photo_station
Skynas
skynas
Calendar
calendar
Video Station
video_station
Drive Server
drive_server
Media Server
media_server
Drive Client
drive_client
Beedrive
beedrive
Note Station
note_station
Dns Server
dns_server
Audio Station
audio_station
Radius Server
radius_server
Beestation Os
beestation_os
Chat
chat
Office
office
File Station
file_station
Dsm
dsm
Assistant
assistant
Sso Server
sso_server
Moments
moments
Safeaccess
safeaccess
Ds Photo+
ds_photo+
Ds File
ds_file
Ds Audio
ds_audio
Cloud Station
cloud_station
Vs960hd
vs960hd
Ds107 Firmware
ds107_firmware
Ds213 Firmware
ds213_firmware
Ds116 Firmware
ds116_firmware
Web Station
web_station
Docker
docker
Mail Station
mail_station
Webdav Server
webdav_server
Usb Copy
usb_copy
Photos
photos
Beephotos
beephotos
Mail Server
mail_server
Presto Client
presto_client
Contacts
contacts
Safe Access
safe_access
Vs360hd
vs360hd
Ds107
ds107
Ds213
ds213
Ds116
ds116
Uc3200
uc3200
Ds3622xs+
ds3622xs+
Fs3410
fs3410
Hd6500
hd6500
Bc500
bc500
Tc500
tc500
Cc400w
cc400w

CVEs (346)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Synology
1Router Manager
May 13, 2026
Aug 28, 2017
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Uncontrolled Resource Consumption vulnerability in SYNO.Core.PortForwarding.Rules in Synology Router Manager (SRM) before 1.1.4-6509 allows remote authenticated attacker to exhaust the memory resources of the machine, ca...Show more
Uncontrolled Resource Consumption vulnerability in SYNO.Core.PortForwarding.Rules in Synology Router Manager (SRM) before 1.1.4-6509 allows remote authenticated attacker to exhaust the memory resources of the machine, causing a denial of service attack.Show less
1Synology
1Diskstation Manager
May 13, 2026
Aug 28, 2017
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Uncontrolled Resource Consumption vulnerability in SYNO.Core.PortForwarding.Rules in Synology DiskStation (DSM) before 6.1.1-15088 allows remote authenticated attacker to exhaust the memory resources of the machine, caus...Show more
Uncontrolled Resource Consumption vulnerability in SYNO.Core.PortForwarding.Rules in Synology DiskStation (DSM) before 6.1.1-15088 allows remote authenticated attacker to exhaust the memory resources of the machine, causing a denial of service attack.Show less
1Synology
1Photo Station
May 13, 2026
Aug 24, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.0-3414 allows remote attackers to inject arbitrary web script or HTML via the image parameter.
1Synology
1Dns Server
May 13, 2026
Aug 24, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in the SYNO.DNSServer.Zone.MasterZoneConf in Synology DNS Server before 2.2.1-3042 allows remote authenticated attackers to write arbitrary files via the domain_name parameter.
1Synology
1Photo Station Uploader
May 13, 2026
Aug 23, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Multiple untrusted search path vulnerabilities in installer in Synology Photo Station Uploader before 1.4.2-084 on Windows allows local attackers to execute arbitrary code and conduct DLL hijacking attack via a Trojan ho...Show more
Multiple untrusted search path vulnerabilities in installer in Synology Photo Station Uploader before 1.4.2-084 on Windows allows local attackers to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current working directory.Show less
1Synology
1Assistant
May 13, 2026
Aug 18, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Multiple untrusted search path vulnerabilities in installer in Synology Assistant before 6.1-15163 on Windows allows local attackers to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfol...Show more
Multiple untrusted search path vulnerabilities in installer in Synology Assistant before 6.1-15163 on Windows allows local attackers to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current working directory.Show less
1Synology
1Download Station
May 13, 2026
Aug 14, 2017
N/A· v4
7.8 HIGH· v3
6.5 MEDIUM· v2
Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsearch directory, which allows remote authenticated users to execute arbitrary code by uploading an exec...Show more
Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsearch directory, which allows remote authenticated users to execute arbitrary code by uploading an executable via unspecified vectors.Show less
1Synology
1Office
May 13, 2026
Aug 14, 2017
N/A· v4
7.8 HIGH· v3
6.5 MEDIUM· v2
Command injection vulnerability in Document.php in Synology Office 2.2.0-1502 and 2.2.1-1506 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the crafted file name of RTF docume...Show more
Command injection vulnerability in Document.php in Synology Office 2.2.0-1502 and 2.2.1-1506 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the crafted file name of RTF documents.Show less
1Synology
1Download Station
May 13, 2026
Aug 14, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows remote authenticated users to download arbitrary local files via crafted...Show more
Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows remote authenticated users to download arbitrary local files via crafted URI.Show less
1Synology
1Video Station
May 13, 2026
Aug 11, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Video Metadata Editor in Synology Video Station before 2.3.0-1435 allows remote authenticated attackers to inject arbitrary web script or HTML via the title parameter.
1Synology
1Chat
May 13, 2026
Aug 11, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Server-side request forgery (SSRF) vulnerability in link preview in Synology Chat before 1.1.0-0806 allows remote authenticated users to access intranet resources via unspecified vectors.
1Synology
1Photo Station
May 13, 2026
Aug 8, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to obtain sensitive system information via unspecified vectors.
1Synology
1Photo Station
May 13, 2026
Aug 8, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to create arbitrary PHP scripts via the type parameter.
1Synology
1Photo Station
May 13, 2026
Aug 8, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain administrator privileges via a crafted serialized payload.
1Synology
1Photo Station
May 13, 2026
Aug 8, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to write arbitrary files via the path parameter.
1Synology
1Photo Station
May 13, 2026
Aug 8, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files without authentication via the logo_upload action.
1Synology
1Diskstation Manager
May 13, 2026
Jul 24, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspecified vectors.
1Synology
1Diskstation Manager
May 13, 2026
Jul 24, 2017
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
A design flaw in SYNO.API.Encryption in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to bypass the encryption protection mechanism via the crafted version parameter.
1Synology
1Video Station
May 13, 2026
Jun 30, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, and 1.6 before 1.6-0847 allow remote authenticated attackers to inject arbitrary web script or HTML...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, and 1.6 before 1.6-0847 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) file name or (2) collection name of videos.Show less
1Synology
1Audio Station
May 13, 2026
Jun 30, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerabilities in Synology Audio Station 5.1 before 5.1-2550 and 5.4 before 5.4-2857 allows remote authenticated attackers to inject arbitrary web script or HTML via the album title.