Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
synology vulnerabilities and exploits
(subscribe to this query)
8.1
CVSSv3
CVE-2022-27626
A vulnerability regarding concurrent execution using shared resource with improper synchronization ('Race Condition') is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote malicious users to execute arbitrary commands via u...
Synology Diskstation Manager
4.8
CVSSv3
CVE-2020-27659
Multiple cross-site scripting (XSS) vulnerabilities in Synology SafeAccess prior to 1.2.3-0234 allow remote malicious users to inject arbitrary web script or HTML via the (1) domain or (2) profile parameter.
Synology Safeaccess
1 Github repository
7.5
CVSSv3
CVE-2021-34812
Use of hard-coded credentials vulnerability in php component in Synology Calendar prior to 2.4.0-0761 allows remote malicious users to obtain sensitive information via unspecified vectors.
Synology Calendar
8.1
CVSSv3
CVE-2018-13298
Channel accessible by non-endpoint vulnerability in privacy page in Synology Android Moments prior to 1.2.3-199 allows man-in-the-middle malicious users to execute arbitrary code via unspecified vectors.
Synology Moments
6.5
CVSSv3
CVE-2018-13299
Relative path traversal vulnerability in Attachment Uploader in Synology Calendar prior to 2.2.2-0532 allows remote authenticated users to upload arbitrary files via the filename parameter.
Synology Calendar
7.9
CVSSv3
CVE-2021-33183
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability container volume management component in Synology Docker prior to 18.09.0-0515 allows local users to read or write arbitrary files via unspecified vectors.
Synology Docker
5.4
CVSSv3
CVE-2019-11825
Cross-site scripting (XSS) vulnerability in Event Editor in Synology Calendar prior to 2.3.0-0615 allows remote malicious users to inject arbitrary web script or HTML via the title parameter.
Synology Calendar
5.4
CVSSv3
CVE-2019-11828
Cross-site scripting (XSS) vulnerability in Chart in Synology Office prior to 3.1.4-2771 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Synology Office
9.8
CVSSv3
CVE-2019-11829
OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar prior to 2.3.1-0617 allows remote malicious users to execute arbitrary commands via the crafted 'X-Real-IP' header.
Synology Calendar
10
CVSSv3
CVE-2022-43931
Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server prior to 1.4.3-0534 and 1.4.4-0635 allows remote malicious users to execute arbitrary commands via unspecified vectors.
Synology Vpn Plus Server
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30051
remote
CVE-2024-27954
CVE-2023-51483
CVE-2023-47782
SSRF
CVE-2024-24715
CVE-2023-52424
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »