Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
synology vulnerabilities and exploits
(subscribe to this query)
3.5
CVSSv2
CVE-2018-8910
Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology Drive prior to 1.0.1-10253 allows remote authenticated users to inject arbitrary web script or HTML via malicious attachments.
Synology Drive
3.5
CVSSv2
CVE-2018-8915
Cross-site scripting (XSS) vulnerability in Notification Center in Synology Calendar prior to 2.1.1-0502 allows remote authenticated users to inject arbitrary web script or HTML via title parameter.
Synology Calendar
NA
CVE-2022-22686
Cross-Site Request Forgery (CSRF) vulnerability in webapi component in Synology Calendar prior to 2.3.4-0631 allows remote authenticated users to hijack the authentication of administrators via unspecified vectors.
Synology Calendar
10
CVSSv2
CVE-2020-27660
SQL injection vulnerability in request.cgi in Synology SafeAccess prior to 1.2.3-0234 allows remote malicious users to execute arbitrary SQL commands via the domain parameter.
Synology Safeaccess
1 Github repository
4
CVSSv2
CVE-2017-11148
Server-side request forgery (SSRF) vulnerability in link preview in Synology Chat prior to 1.1.0-0806 allows remote authenticated users to access intranet resources via unspecified vectors.
Synology Chat
4.6
CVSSv2
CVE-2017-11158
Multiple untrusted search path vulnerabilities in the installer in Synology Cloud Station Drive prior to 4.2.5-4396 on Windows allow local malicious users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32...
Synology Cloud Station Drive
4.6
CVSSv2
CVE-2017-11160
Multiple untrusted search path vulnerabilities in installer in Synology Assistant prior to 6.1-15163 on Windows allows local malicious users to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwm...
Synology Assistant
3.5
CVSSv2
CVE-2018-8921
Cross-site scripting (XSS) vulnerability in File Sharing Notify Toast in Synology Drive prior to 1.0.2-10275 allows remote authenticated users to inject arbitrary web script or HTML via the malicious file name.
Synology Drive
3.5
CVSSv2
CVE-2018-8924
Cross-site scripting (XSS) vulnerability in Title Tootip in Synology Office prior to 3.0.3-2143 allows remote authenticated users to inject arbitrary web script or HTML via the malicious file name.
Synology Office
4
CVSSv2
CVE-2018-8927
Improper authorization vulnerability in SYNO.Cal.Event in Calendar prior to 2.1.2-0511 allows remote authenticated users to create arbitrary events via the (1) cal_id or (2) original_cal_id parameter.
Synology Calendar
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »