CVE & Exploit Intelligence Database

Updated 56m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
6 results Clear all
CVE-2024-4464 7.5 HIGH EPSS 0.00
Synology Media Server <2.2.0-3325 - Auth Bypass
Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-2680, 2.0.5-3152 and 2.2.0-3325 allows remote attackers to read specific files via unspecified vectors.
CWE-639 Dec 18, 2024
CVE-2022-27614 5.3 MEDIUM EPSS 0.00
Synology Media Server < 1.8.1-2876 - Information Disclosure
Exposure of sensitive information to an unauthorized actor vulnerability in web server in Synology Media Server before 1.8.1-2876 allows remote attackers to obtain sensitive information via unspecified vectors.
CWE-200 Jul 28, 2022
CVE-2022-22683 10.0 CRITICAL EPSS 0.04
Synology Media Server < 1.8.1-2876 - Buffer Overflow
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allows remote attackers to execute arbitrary code via unspecified vectors.
CWE-120 Jul 28, 2022
CVE-2021-34808 5.8 MEDIUM EPSS 0.00
Synology Media Server < 1.8.3-2881 - SSRF
Server-Side Request Forgery (SSRF) vulnerability in cgi component in Synology Media Server before 1.8.3-2881 allows remote attackers to access intranet resources via unspecified vectors.
CWE-918 Jun 18, 2021
CVE-2021-33180 7.3 HIGH EPSS 0.00
Synology Media Server <1.8.1-2876 - SQL Injection
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CWE-89 Jun 01, 2021
CVE-2018-8914 7.3 HIGH EPSS 0.00
Synology Media Server < 1.4-2654 - SQL Injection
SQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote attackers to execute arbitrary SQL commands via the ObjectID parameter.
CWE-89 May 10, 2018