synology

329 tracked vulnerabilities.

CVE-2021-43927 MEDIUM
Synology DSM <7.0.1-42218-2 - SQL Injection
Feb 07, 2022
CVSS 4.7
EPSS 0.00
CVE-2021-43926 MEDIUM
Synology DSM <7.0.1-42218-2 - SQL Injection
Feb 07, 2022
CVSS 4.7
EPSS 0.00
CVE-2021-43925 MEDIUM
Synology DSM <7.0.1-42218-2 - SQL Injection
Feb 07, 2022
CVSS 4.7
EPSS 0.00
CVE-2021-29087 HIGH
Synology DiskStation Manager < 6.2.3-25426-3 - Path Traversal and Arbitrary File Write via WebAPI Component
Jun 23, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-29086 MEDIUM
Synology DSM <6.2.3-25426-3 & DSM UC <3.1-23033 Sensitive Info Exposure via WebAPI
Jun 23, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-29085 HIGH
Synology DiskStation Manager 6.2-6.2.3-25426-3 - Arbitrary File Read via File Sharing Management Component
Jun 23, 2021
CVSS 8.6
EPSS 0.00
CVE-2021-29084 HIGH
Synology DSM <6.2.3-25426-3 & DSM UC <3.1-23033 Arbitrary File Read
Jun 23, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-27649 CRITICAL
Synology DSM <6.2.3-25426-3 - Use After Free
Jun 23, 2021
CVSS 9.8
EPSS 0.01
CVE-2021-34812 MEDIUM
Synology Calendar < 2.4.0-0761 - Use of Hard-coded Credentials in PHP Component
Jun 18, 2021
CVSS 5.8
EPSS 0.00
CVE-2021-34811 MEDIUM
Synology Download Station < 3.8.16-3566 - Authenticated Server-Side Request Forgery in Task Management Component
Jun 18, 2021
CVSS 5.0
EPSS 0.00
CVE-2021-34810 CRITICAL
Synology Download Station < 3.8.16-3566 - Authenticated Remote Code Execution via CGI Component
Jun 18, 2021
CVSS 9.9
EPSS 0.01
CVE-2021-34809 CRITICAL
Synology Download Station < 3.8.16-3566 - Authenticated Remote Code Execution via Task Management Component
Jun 18, 2021
CVSS 9.9
EPSS 0.02
CVE-2021-34808 MEDIUM
Synology Media Server < 1.8.3-2881 - Server-Side Request Forgery via CGI Component
Jun 18, 2021
CVSS 5.8
EPSS 0.00
CVE-2021-29089 CRITICAL
Synology Photo Station < 6.8.14-3500 - SQL Injection in Thumbnail Component
Jun 02, 2021
CVSS 9.8
EPSS 0.01
CVE-2021-29091 HIGH
Synology Photo Station < 6.8.14-3500 - Authenticated Path Traversal and Arbitrary File Write
Jun 02, 2021
CVSS 7.7
EPSS 0.00
CVE-2021-29090 HIGH
Synology Photo Station < 6.8.14-3500 - Authenticated SQL Injection
Jun 02, 2021
CVSS 7.2
EPSS 0.01
CVE-2021-33184 HIGH
Synology Download Station <3.8.15-3563 - SSRF
Jun 01, 2021
CVSS 7.7
EPSS 0.00
CVE-2021-33183 HIGH
Synology Docker <18.09.0-0515 - Path Traversal
Jun 01, 2021
CVSS 7.9
EPSS 0.00
CVE-2021-33182 MEDIUM
Synology DSM <6.2.4-25553 - Path Traversal
Jun 01, 2021
CVSS 5.0
EPSS 0.00
CVE-2021-33181 MEDIUM
Synology Video Station <2.4.10-1632 - SSRF
Jun 01, 2021
CVSS 6.6
EPSS 0.00
CVE-2021-33180 HIGH
Synology Media Server <1.8.1-2876 - SQL Injection
Jun 01, 2021
CVSS 7.3
EPSS 0.00
CVE-2021-29092 HIGH
Synology Photo Station 6.8-6.8.13 - Authenticated Arbitrary File Upload and Remote Code Execution
Jun 01, 2021
CVSS 8.8
EPSS 0.01
CVE-2021-29088 HIGH
Synology DiskStation Manager < 6.2.4-25553 - Local Arbitrary Code Execution via Path Traversal in CGI Component
Jun 01, 2021
CVSS 7.8
EPSS 0.00
CVE-2021-31439 HIGH
Synology DiskStation Manager 6.2-6.2.3-25426-3 - Unauthenticated Heap-based Buffer Overflow in Netatalk DSI Processing
May 21, 2021
CVSS 8.8
EPSS 0.01
CVE-2021-27648 CRITICAL
Synology Antivirus Essential <1.4.8-2801 - Privilege Escalation
Apr 28, 2021
CVSS 9.0
EPSS 0.10