Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
synology vulnerabilities and exploits
(subscribe to this query)
409
VMScore
CVE-2017-11160
Multiple untrusted search path vulnerabilities in installer in Synology Assistant prior to 6.1-15163 on Windows allows local malicious users to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwm...
Synology Assistant
187
VMScore
CVE-2019-11820
Information exposure through process environment vulnerability in Synology Calendar prior to 2.3.3-0620 allows local users to obtain credentials via cmdline.
Synology Calendar
312
VMScore
CVE-2019-11825
Cross-site scripting (XSS) vulnerability in Event Editor in Synology Calendar prior to 2.3.0-0615 allows remote malicious users to inject arbitrary web script or HTML via the title parameter.
Synology Calendar
578
VMScore
CVE-2019-11826
Relative path traversal vulnerability in SYNO.PhotoTeam.Upload.Item in Synology Moments prior to 1.3.0-0691 allows remote authenticated users to upload arbitrary files via the name parameter.
Synology Moments
312
VMScore
CVE-2019-11828
Cross-site scripting (XSS) vulnerability in Chart in Synology Office prior to 3.1.4-2771 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Synology Office
668
VMScore
CVE-2019-11829
OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar prior to 2.3.1-0617 allows remote malicious users to execute arbitrary commands via the crafted 'X-Real-IP' header.
Synology Calendar
445
VMScore
CVE-2018-13297
Information exposure vulnerability in SYNO.SynologyDrive.Files in Synology Drive prior to 1.1.2-10562 allows remote malicious users to obtain sensitive system information via the dsm_path parameter.
Synology Drive
356
VMScore
CVE-2018-13299
Relative path traversal vulnerability in Attachment Uploader in Synology Calendar prior to 2.2.2-0532 allows remote authenticated users to upload arbitrary files via the filename parameter.
Synology Calendar
312
VMScore
CVE-2018-8910
Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology Drive prior to 1.0.1-10253 allows remote authenticated users to inject arbitrary web script or HTML via malicious attachments.
Synology Drive
312
VMScore
CVE-2018-8915
Cross-site scripting (XSS) vulnerability in Notification Center in Synology Calendar prior to 2.1.1-0502 allows remote authenticated users to inject arbitrary web script or HTML via title parameter.
Synology Calendar
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
privilege escalation
CVE-2024-20696
CVE-2024-29829
CVE-2024-33999
CVE-2024-35646
physical
CVE-2024-24919
CVE-2024-31030
local users
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »