Synology
synology
351 CVEs • 102 products
Products (102)
Click to collapseToggle
Products (102)
Click to collapse
CVEs (351)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated user...Show more |
1Synology 1Active Backup For Microsoft 365 Jun 17, 2026 May 16, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive information via unspecified vectors. |
Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows remote attackers to read arbitrary files via unspecified vectors. |
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in the system syncing daemon in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows...Show more |
Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to obtain administrator cre...Show more |
1Synology 2Beestation Os Diskstation ManagerJun 17, 2026 Mar 19, 2025 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7...Show more |
1Synology 3Bc500 Firmware Cc400w FirmwareTc500 FirmwareJun 17, 2026 Mar 19, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability regarding out-of-bounds read is found in the video interface. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camera Firmware versions be...Show more |
2Syncology Synology3Replication Service Replication ServiceUnified ControllerJun 17, 2026 Mar 19, 2025 N/A· v4 10.0 CRITICAL· v3 N/A· v2 Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attacker...Show more |
1Synology 2Beestation Os Diskstation ManagerJun 17, 2026 Mar 19, 2025 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69...Show more |
Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows man-in-the-middle attackers to hijack the authenticat...Show more |
1Synology 2Beestation Os Diskstation ManagerJun 17, 2026 Mar 19, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-...Show more |
1Synology 1Active Backup For Business Agent Jun 17, 2026 Feb 13, 2025 N/A· v4 2.7 LOW· v3 N/A· v2 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in share file list functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows r...Show more |
1Synology 1Active Backup For Business Agent Jun 17, 2026 Feb 13, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 a...Show more |
1Synology 1Active Backup For Business Agent Jun 17, 2026 Feb 13, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows rem...Show more |
Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-2680, 2.0.5-3152 and 2.2.0-3325 allows remote attackers to read specific files via unspecified vecto...Show more |
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with...Show more |
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated u...Show more |
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Router Port Forward functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated us...Show more |
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect MAC Filter functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticate...Show more |
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Network WOL functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users to r...Show more |