Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
synology vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2021-27649
Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) prior to 6.2.3-25426-3 allows remote malicious users to execute arbitrary code via unspecified vectors.
Synology Diskstation Manager
Synology Diskstation Manager Unified Controller
5.3
CVSSv3
CVE-2021-34808
Server-Side Request Forgery (SSRF) vulnerability in cgi component in Synology Media Server prior to 1.8.3-2881 allows remote malicious users to access intranet resources via unspecified vectors.
Synology Media Server
8.8
CVSSv3
CVE-2021-34809
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in task management component in Synology Download Station prior to 3.8.16-3566 allows remote authenticated users to execute arbitrary code via unspecified vectors.
Synology Download Station
8.8
CVSSv3
CVE-2021-34810
Improper privilege management vulnerability in cgi component in Synology Download Station prior to 3.8.16-3566 allows remote authenticated users to execute arbitrary code via unspecified vectors.
Synology Download Station
4.3
CVSSv3
CVE-2021-34811
Server-Side Request Forgery (SSRF) vulnerability in task management component in Synology Download Station prior to 3.8.16-3566 allows remote authenticated users to access intranet resources via unspecified vectors.
Synology Download Station
7.5
CVSSv3
CVE-2021-34812
Use of hard-coded credentials vulnerability in php component in Synology Calendar prior to 2.4.0-0761 allows remote malicious users to obtain sensitive information via unspecified vectors.
Synology Calendar
9.8
CVSSv3
CVE-2021-29089
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in thumbnail component in Synology Photo Station prior to 6.8.14-3500 allows remote attackers users to execute arbitrary SQL commands via unspecified vectors.
Synology Photo Station
6.5
CVSSv3
CVE-2021-29091
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file management component in Synology Photo Station prior to 6.8.14-3500 allows remote authenticated users to write arbitrary files via unspecified vectors.
Synology Photo Station
7.2
CVSSv3
CVE-2021-29090
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in PHP component in Synology Photo Station prior to 6.8.14-3500 allows remote authenticated users to execute arbitrary SQL command via unspecified vectors.
Synology Photo Station
8.8
CVSSv3
CVE-2021-29092
Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station prior to 6.8.14-3500 allows remote authenticated users to execute arbitrary code via unspecified vectors.
Synology Photo Station
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-17519
open redirect
CVE-2024-21683
cache poisoning
CVE-2021-47524
CVE-2021-47521
CVE-2024-5229
CVE-2021-47560
local
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »