vendor

synology

22 thingsrelated by NVD

Its products

diskstation manager 8 beedrive 5 router manager 5 diskstation manager unified controller 3 active backup for business 1 active backup for business agent 1 activeprotect agent 1 assistant 1 beestation os 1 c2 identity edge server 1 contacts 1 mail server 1 safe access 1

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with…
CVE-2025-66593
Severity medium
An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write…
CVE-2025-66592
Severity medium
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop…
CVE-2025-54160
Severity high
Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete…
CVE-2025-54159
Severity high
Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local…
CVE-2025-54158
Severity high
A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.
CVE-2025-30028
Severity high
A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.
CVE-2025-29846
Severity high
A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.
CVE-2025-29845
Severity medium
A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.
CVE-2025-29844
Severity medium
A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.
CVE-2025-29843
Severity medium
An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote…
CVE-2025-14713
Severity high
Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with…
CVE-2025-13593
Severity medium
Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and…
CVE-2025-13392
Severity critical
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology…
CVE-2025-13167
Severity medium
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before…
CVE-2025-12686
Severity critical
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Synology Safe Access…
CVE-2025-10466
Severity medium
Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users to write arbitrary…
CVE-2025-8074
Severity medium
A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some…
CVE-2025-2848
Severity medium
Out-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology…
CVE-2024-45539
Severity high
Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and…
CVE-2024-45538
Severity critical
Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before…
CVE-2024-5401
Severity high
Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local…
CVE-2023-52945
Severity high