Filtered by vendor Synology
Subscribe
Total
351 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-47273 | 1 Synology | 1 Hyper Backup | 2026-07-22 | N/A | 4.3 MEDIUM |
| An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors. | |||||
| CVE-2022-49036 | 1 Synology | 1 Active Backup For Business Recovery Media Creator | 2026-07-22 | N/A | 7.8 HIGH |
| An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors. | |||||
| CVE-2022-49042 | 1 Synology | 1 Hyper Backup Explorer | 2026-07-22 | N/A | 7.8 HIGH |
| An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors. | |||||
| CVE-2024-47263 | 1 Synology | 1 Hyper Backup | 2026-07-22 | N/A | 4.1 MEDIUM |
| An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing non-sensitive information via unspecified vectors. | |||||
| CVE-2023-52951 | 1 Synology | 1 Note Station Client | 2026-07-22 | N/A | 5.9 MEDIUM |
| A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential. | |||||
| CVE-2026-3091 | 1 Synology | 1 Presto Client | 2026-06-17 | N/A | 6.7 MEDIUM |
| An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files and conduct denial-of-service during installation by placing a malicious DLL in advance in the same directory as the installer. | |||||
| CVE-2026-2237 | 1 Synology | 2 Diskstation Manager, Storage Manager | 2026-06-17 | N/A | 6.2 MEDIUM |
| A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information. | |||||
| CVE-2025-8074 | 1 Synology | 1 Beedrive | 2026-06-17 | N/A | 5.6 MEDIUM |
| Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users to write arbitrary files with non-sensitive information via unspecified vectors. | |||||
| CVE-2025-66593 | 1 Synology | 1 Assistant | 2026-06-17 | N/A | 6.1 MEDIUM |
| An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. | |||||
| CVE-2025-66592 | 1 Synology | 1 Active Backup For Business Agent | 2026-06-17 | N/A | 6.1 MEDIUM |
| An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. | |||||
| CVE-2025-54160 | 1 Synology | 1 Beedrive | 2026-06-17 | N/A | 7.8 HIGH |
| Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors. | |||||
| CVE-2025-54159 | 1 Synology | 1 Beedrive | 2026-06-17 | N/A | 7.5 HIGH |
| Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitrary files via unspecified vectors. | |||||
| CVE-2025-54158 | 1 Synology | 1 Beedrive | 2026-06-17 | N/A | 7.8 HIGH |
| Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors. | |||||
| CVE-2025-4679 | 1 Synology | 1 Active Backup For Microsoft 365 | 2026-06-17 | N/A | 6.5 MEDIUM |
| A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive information via unspecified vectors. | |||||
| CVE-2025-30028 | 1 Synology | 2 Active Backup For Business, Diskstation Manager | 2026-06-17 | N/A | 8.6 HIGH |
| A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files. | |||||
| CVE-2025-2848 | 1 Synology | 2 Diskstation Manager, Mail Server | 2026-06-17 | N/A | 6.3 MEDIUM |
| A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical functions. | |||||
| CVE-2025-29846 | 1 Synology | 1 Router Manager | 2026-06-17 | N/A | 7.2 HIGH |
| A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages. | |||||
| CVE-2025-29845 | 1 Synology | 1 Router Manager | 2026-06-17 | N/A | 4.3 MEDIUM |
| A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files. | |||||
| CVE-2025-29844 | 1 Synology | 1 Router Manager | 2026-06-17 | N/A | 4.3 MEDIUM |
| A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information. | |||||
| CVE-2025-29843 | 1 Synology | 1 Router Manager | 2026-06-17 | N/A | 5.4 MEDIUM |
| A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files. | |||||
