Vulnerabilities (CVE)

Filtered by vendor Synology Subscribe
Total 351 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-47273 1 Synology 1 Hyper Backup 2026-07-22 N/A 4.3 MEDIUM
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors.
CVE-2022-49036 1 Synology 1 Active Backup For Business Recovery Media Creator 2026-07-22 N/A 7.8 HIGH
An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.
CVE-2022-49042 1 Synology 1 Hyper Backup Explorer 2026-07-22 N/A 7.8 HIGH
An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.
CVE-2024-47263 1 Synology 1 Hyper Backup 2026-07-22 N/A 4.1 MEDIUM
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing non-sensitive information via unspecified vectors.
CVE-2023-52951 1 Synology 1 Note Station Client 2026-07-22 N/A 5.9 MEDIUM
A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential.
CVE-2026-3091 1 Synology 1 Presto Client 2026-06-17 N/A 6.7 MEDIUM
An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files and conduct denial-of-service during installation by placing a malicious DLL in advance in the same directory as the installer.
CVE-2026-2237 1 Synology 2 Diskstation Manager, Storage Manager 2026-06-17 N/A 6.2 MEDIUM
A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information.
CVE-2025-8074 1 Synology 1 Beedrive 2026-06-17 N/A 5.6 MEDIUM
Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users to write arbitrary files with non-sensitive information via unspecified vectors.
CVE-2025-66593 1 Synology 1 Assistant 2026-06-17 N/A 6.1 MEDIUM
An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
CVE-2025-66592 1 Synology 1 Active Backup For Business Agent 2026-06-17 N/A 6.1 MEDIUM
An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
CVE-2025-54160 1 Synology 1 Beedrive 2026-06-17 N/A 7.8 HIGH
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors.
CVE-2025-54159 1 Synology 1 Beedrive 2026-06-17 N/A 7.5 HIGH
Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitrary files via unspecified vectors.
CVE-2025-54158 1 Synology 1 Beedrive 2026-06-17 N/A 7.8 HIGH
Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors.
CVE-2025-4679 1 Synology 1 Active Backup For Microsoft 365 2026-06-17 N/A 6.5 MEDIUM
A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive information via unspecified vectors.
CVE-2025-30028 1 Synology 2 Active Backup For Business, Diskstation Manager 2026-06-17 N/A 8.6 HIGH
A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.
CVE-2025-2848 1 Synology 2 Diskstation Manager, Mail Server 2026-06-17 N/A 6.3 MEDIUM
A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical functions.
CVE-2025-29846 1 Synology 1 Router Manager 2026-06-17 N/A 7.2 HIGH
A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.
CVE-2025-29845 1 Synology 1 Router Manager 2026-06-17 N/A 4.3 MEDIUM
A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.
CVE-2025-29844 1 Synology 1 Router Manager 2026-06-17 N/A 4.3 MEDIUM
A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.
CVE-2025-29843 1 Synology 1 Router Manager 2026-06-17 N/A 5.4 MEDIUM
A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.