Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
synology vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv3
CVE-2021-34811
Server-Side Request Forgery (SSRF) vulnerability in task management component in Synology Download Station prior to 3.8.16-3566 allows remote authenticated users to access intranet resources via unspecified vectors.
Synology Download Station
5.4
CVSSv3
CVE-2018-8912
Cross-site scripting (XSS) vulnerability in SYNO.NoteStation.Note in Synology Note Station prior to 2.5.1-0844 allows remote authenticated users to inject arbitrary web script or HTML via the commit_msg parameter.
Synology Note Station
9.8
CVSSv3
CVE-2018-8914
SQL injection vulnerability in UPnP DMA in Synology Media Server prior to 1.7.6-2842 and prior to 1.4-2654 allows remote malicious users to execute arbitrary SQL commands via the ObjectID parameter.
Synology Media Server
8.8
CVSSv3
CVE-2018-8916
Unverified password change vulnerability in Change Password in Synology DiskStation Manager (DSM) prior to 6.2-23739 allows remote authenticated users to reset password without verification.
Synology Diskstation Manager
5.4
CVSSv3
CVE-2018-8917
Cross-site scripting (XSS) vulnerability in info.cgi in Synology DiskStation Manager (DSM) prior to 6.1.6-15266 allows remote malicious users to inject arbitrary web script or HTML via the host parameter.
Synology Diskstation Manager
5.4
CVSSv3
CVE-2018-8918
Cross-site scripting (XSS) vulnerability in info.cgi in Synology Router Manager (SRM) prior to 1.1.7-6941 allows remote malicious users to inject arbitrary web script or HTML via the host parameter.
Synology Router Manager
9.8
CVSSv3
CVE-2018-8919
Information exposure vulnerability in SYNO.Core.Desktop.SessionData in Synology DiskStation Manager (DSM) prior to 6.1.6-15266 allows remote malicious users to steal credentials via unspecified vectors.
Synology Diskstation Manager
7.2
CVSSv3
CVE-2018-8920
Improper neutralization of escape vulnerability in Log Exporter in Synology DiskStation Manager (DSM) prior to 6.1.6-15266 allows remote malicious users to inject arbitrary content to have an unspecified impact by exporting an archive in CSV format.
Synology Diskstation Manager
5.4
CVSSv3
CVE-2018-8923
Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology File Station prior to 1.1.4-0122 allows remote authenticated users to inject arbitrary web script or HTML via malicious attachments.
Synology File Station
8.8
CVSSv3
CVE-2018-8926
Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station prior to 6.8.5-3471 and prior to 6.3-2975 allows remote authenticated users to conduct privilege escalation attacks via the fullname parameter.
Synology Photo Station
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
bypass
open redirect
CVE-2024-4358
CVE-2024-24199
CVE-2024-5550
CVE-2024-5305
CVE-2024-30373
CVE-2024-1800
deserialization
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
6
7
8
9
10
NEXT »