Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
synology vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv2
CVE-2021-34810
Improper privilege management vulnerability in cgi component in Synology Download Station prior to 3.8.16-3566 allows remote authenticated users to execute arbitrary code via unspecified vectors.
Synology Download Station
4
CVSSv2
CVE-2021-34811
Server-Side Request Forgery (SSRF) vulnerability in task management component in Synology Download Station prior to 3.8.16-3566 allows remote authenticated users to access intranet resources via unspecified vectors.
Synology Download Station
7.5
CVSSv2
CVE-2021-33180
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in cgi component in Synology Media Server prior to 1.8.1-2876 allows remote malicious users to execute arbitrary SQL commands via unspecified vectors.
Synology Media Server
6.5
CVSSv2
CVE-2021-33181
Server-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station prior to 2.4.10-1632 allows remote authenticated users to send arbitrary request to intranet resources via unspecified vectors.
Synology Video Station
4
CVSSv2
CVE-2021-33182
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in PDF Viewer component in Synology DiskStation Manager (DSM) prior to 6.2.4-25553 allows remote authenticated users to read limited files via unspecified vectors.
Synology Diskstation Manager
4
CVSSv2
CVE-2021-33184
Server-Side request forgery (SSRF) vulnerability in task management component in Synology Download Station prior to 3.8.15-3563 allows remote authenticated users to read arbitrary files via unspecified vectors.
Synology Download Station
4.3
CVSSv2
CVE-2015-6909
Cross-site scripting (XSS) vulnerability in the "Create download task via file upload" feature in Synology Download Station prior to 3.5-2962 allows remote malicious users to inject arbitrary web script or HTML via the name element in the Info dictionary in a torrent fi...
Synology Download Station
7.5
CVSSv2
CVE-2015-6910
SQL injection vulnerability in Synology Video Station prior to 1.5-0757 allows remote malicious users to execute arbitrary SQL commands via the id parameter to audiotrack.cgi.
Synology Video Station
7.5
CVSSv2
CVE-2015-6911
SQL injection vulnerability in Synology Video Station prior to 1.5-0763 allows remote malicious users to execute arbitrary SQL commands via the id parameter to watchstatus.cgi.
Synology Video Station
1 EDB exploit
4.3
CVSSv2
CVE-2015-6913
Cross-site scripting (XSS) vulnerability in the "Create download task via URL" feature in Synology Download Station prior to 3.5-2967 allows remote malicious users to inject arbitrary web script or HTML via the urls parameter in an add_url_task action to dlm/downloadman...
Synology Download Station
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3581
reflected XSS
CVE-2024-26925
CVE-2024-27956
LFI
CVE-2024-3607
CVE-2024-3107
CVE-2024-3295
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »