Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
diskstation manager vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2018-13293
Cross-site scripting (XSS) vulnerability in Control Panel SSO Settings in Synology DiskStation Manager (DSM) prior to 6.2.1-23824 allows remote authenticated users to inject arbitrary web script or HTML via the URL parameter.
Synology Diskstation Manager
8.1
CVSSv3
CVE-2022-27610
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) prior to 6.2.3-25423 allows remote authenticated users to delete arbitrary files via unspecified vectors.
Synology Diskstation Manager
7.2
CVSSv3
CVE-2022-27616
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in webapi component in Synology DiskStation Manager (DSM) prior to 7.0.1-42218-3 allows remote authenticated users to execute arbitrary commands via unspecified vect...
Synology Diskstation Manager
4.3
CVSSv3
CVE-2022-27622
Server-Side Request Forgery (SSRF) vulnerability in Package Center functionality in Synology DiskStation Manager (DSM) prior to 7.1-42661 allows remote authenticated users to access intranet resources via unspecified vectors.
Synology Diskstation Manager
9.1
CVSSv3
CVE-2022-27623
Missing authentication for critical function vulnerability in iSCSI management functionality in Synology DiskStation Manager (DSM) prior to 7.1-42661 allows remote malicious users to read or write arbitrary files via unspecified vectors.
Synology Diskstation Manager
NA
CVE-2015-4655
Cross-site scripting (XSS) vulnerability in Synology DiskStation Manager (DSM) prior to 5.2-5565 Update 1 allows remote malicious users to inject arbitrary web script or HTML via the "compound" parameter to entry.cgi.
Synology Diskstation Manager
4.9
CVSSv3
CVE-2022-22679
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in support service management in Synology DiskStation Manager (DSM) prior to 7.0.1-42218-2 allows remote authenticated users to write arbitrary files via unspecified vectors.
Synology Diskstation Manager
7.5
CVSSv3
CVE-2017-9553
A design flaw in SYNO.API.Encryption in Synology DiskStation Manager (DSM) prior to 6.1.3-15152 allows remote malicious users to bypass the encryption protection mechanism via the crafted version parameter.
Synology Diskstation Manager
5.3
CVSSv3
CVE-2017-9554
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) prior to 6.1.3-15152 allows remote malicious users to enumerate valid usernames via unspecified vectors.
Synology Diskstation Manager
1 EDB exploit
2 Github repositories
7.2
CVSSv3
CVE-2017-12075
Command injection vulnerability in EZ-Internet in Synology DiskStation Manager (DSM) prior to 6.2-23739 allows remote authenticated users to execute arbitrary command via the username parameter.
Synology Diskstation Manager
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4946
CVE-2024-30309
CVE-2024-4761
CVE-2024-30051
type confusion
memory leak
CVE-2024-30293
reflected XSS
CVE-2024-3126
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »