Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
synology vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2018-13297
Information exposure vulnerability in SYNO.SynologyDrive.Files in Synology Drive prior to 1.1.2-10562 allows remote malicious users to obtain sensitive system information via the dsm_path parameter.
Synology Drive
6.8
CVSSv2
CVE-2018-13298
Channel accessible by non-endpoint vulnerability in privacy page in Synology Android Moments prior to 1.2.3-199 allows man-in-the-middle malicious users to execute arbitrary code via unspecified vectors.
Synology Moments
4
CVSSv2
CVE-2018-13299
Relative path traversal vulnerability in Attachment Uploader in Synology Calendar prior to 2.2.2-0532 allows remote authenticated users to upload arbitrary files via the filename parameter.
Synology Calendar
3.5
CVSSv2
CVE-2020-27659
Multiple cross-site scripting (XSS) vulnerabilities in Synology SafeAccess prior to 1.2.3-0234 allow remote malicious users to inject arbitrary web script or HTML via the (1) domain or (2) profile parameter.
Synology Safeaccess
1 Github repository
3.6
CVSSv2
CVE-2021-33183
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability container volume management component in Synology Docker prior to 18.09.0-0515 allows local users to read or write arbitrary files via unspecified vectors.
Synology Docker
3.5
CVSSv2
CVE-2018-8915
Cross-site scripting (XSS) vulnerability in Notification Center in Synology Calendar prior to 2.1.1-0502 allows remote authenticated users to inject arbitrary web script or HTML via title parameter.
Synology Calendar
NA
CVE-2022-22686
Cross-Site Request Forgery (CSRF) vulnerability in webapi component in Synology Calendar prior to 2.3.4-0631 allows remote authenticated users to hijack the authentication of administrators via unspecified vectors.
Synology Calendar
5
CVSSv2
CVE-2021-34812
Use of hard-coded credentials vulnerability in php component in Synology Calendar prior to 2.4.0-0761 allows remote malicious users to obtain sensitive information via unspecified vectors.
Synology Calendar
NA
CVE-2022-3576
A vulnerability regarding out-of-bounds read is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote malicious users to obtain sensitive information via unspecified vectors. The following models with Synology DiskStation Manager (DSM) ...
Synology Diskstation Manager
3.5
CVSSv2
CVE-2019-11828
Cross-site scripting (XSS) vulnerability in Chart in Synology Office prior to 3.1.4-2771 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Synology Office
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3201
CVE-2024-4779
CVE-2024-35090
CVE-2024-5084
hard-coded
CVE-2024-4985
HTML injection
CVE-2024-33655
local file inclusion
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »