Synology Latest Vulnerabilities

November 15

Synology Task Manager Vulnerability Allows Arbitrary Code Execution

CVE-2024-10443
SynologyBeephotos9.8CRITICAL

September 26

Synology Active Backup for Business vulnerability exposed local users' credentials

CVE-2023-52949
SynologySynology Active Backup...5.5MEDIUM

Missing Encryption of Sensitive Data in Synology Active Backup for Business Agent Could Lead to User Credentials Theft

CVE-2023-52948
SynologySynology Active Backup...5MEDIUM

Local Users Can Logout Client Via Unspecified Vectors, Backup Functionality Unaffected

CVE-2023-52947
SynologySynology Active Backup...3.3LOW

Man-in-the-Middle Attack on Synology Active Backup for Business Lets Hackers Access User Credentials

CVE-2023-52950
SynologySynology Active Backup...5.3MEDIUM

Buffer Copy Vulnerability Affects Synology Drive Client

CVE-2022-49041
SynologySynology Drive Client4.4MEDIUM

Synology Drive Client Exploited by Classic Buffer Overflow

CVE-2022-49040
SynologySynology Drive Client4.4MEDIUM

Arbitrary Command Execution Vulnerability in Synology Drive Client

CVE-2022-49039
SynologySynology Drive Client6.7MEDIUM

Untrusted Control Sphere Vulnerability Affects Synology Drive Client

CVE-2022-49038
SynologySynology Drive Client7.8HIGH

Synology Drive Client vulnerability allows remote access to sensitive information

CVE-2022-49037
SynologySynology Drive Client6.5MEDIUM

Classic Buffer Overflow Vulnerability Affects Synology Drive Client

CVE-2023-52946
SynologySynology Drive Client8.2HIGH

June 28

Authentication Bypass Vulnerability Affects Synology Cameras

CVE-2024-39350
SynologyCamera Firmware7.5HIGH

Synology Router Manager (SRM) Vulnerability Allows Arbitrary Code Execution

CVE-2024-39348
SynologySynology Router Manage...7.5HIGH

Synology Router Manager (SRM) Vulnerability Allows Man-in-the-Middle Attacks on Sensitive Intranet Resources

CVE-2024-39347
SynologySynology Router Manage...5.9MEDIUM

Firmware Upgrade Vulnerability Allows Bypass of Integrity Check

CVE-2024-39352
SynologyCamera Firmware4.9MEDIUM

Arbitrary Command Execution Vulnerability in Synology Camera Firmware

CVE-2024-39351
SynologyCamera Firmware7.2HIGH

Remote Code Execution Vulnerability in Synology Camera Firmware

CVE-2024-39349
SynologyCamera Firmware9.8CRITICAL

Path Traversal Vulnerability Affects Synology Cameras

CVE-2023-47803
SynologyCamera Firmware5.3MEDIUM

Arbitrary Command Execution Vulnerability in Synology Camera Firmware

CVE-2023-47802
SynologyCamera Firmware7.2HIGH

June 4

Buffer Copy Vulnerability Affects Synology Login Service

CVE-2024-5463
SynologyCamera Firmware6.5MEDIUM

March 28

Bypass Security Constraints Vulnerability Affects Synology Surveillance Station

CVE-2024-29241
SynologySurveillance Station9.9CRITICAL

Synology Surveillance Station vulnerability allows remote DoS attacks

CVE-2024-29240
SynologySurveillance Station4.3MEDIUM

CVE-2024-29239
SynologySurveillance Station5.4MEDIUM

CVE-2024-29238
SynologySurveillance Station5.4MEDIUM

CVE-2024-29237
SynologySurveillance Station5.4MEDIUM

CVE-2024-29236
SynologySurveillance Station5.4MEDIUM

CVE-2024-29235
SynologySurveillance Station5.4MEDIUM

SQL Injection Vulnerability in Synology Surveillance Station

CVE-2024-29234
SynologySurveillance Station5.4MEDIUM

SQL Injection Vulnerability in Synology Surveillance Station

CVE-2024-29233
SynologySurveillance Station5.4MEDIUM

CVE-2024-29232
SynologySurveillance Station5.4MEDIUM

Remote Authenticated Users Can Bypass Security Constraints via Unspecified Vectors

CVE-2024-29231
SynologySurveillance Station5.4MEDIUM

CVE-2024-29230
SynologySurveillance Station5.4MEDIUM

Remote Authenticated Users Can Obtain Sensitive Information via Unspecified Vectors in GetLiveViewPath WebAPI Component

CVE-2024-29229
SynologySurveillance Station7.7HIGH

Remote Authenticated Users Can Obtain Sensitive Information via Unspecified Vectors in GetStmUrlPath WebAPI Component

CVE-2024-29228
SynologySurveillance Station7.7HIGH

CVE-2024-29227
SynologySurveillance Station5.4MEDIUM

January 24

CVE-2024-0854
SynologyDiskStation Manager (DSM)5.4MEDIUM

November 7

CVE-2023-5748
SynologySynology SSL VPN Client5.5MEDIUM

October 25

CVE-2023-5746
SynologyCamera Firmware9.8CRITICAL

August 31

CVE-2023-41741
SynologySynology Router Manage...5.3MEDIUM

CVE-2023-41740
SynologySynology Router Manage...5.3MEDIUM

CVE-2023-41739
SynologySynology Router Manage...4.9MEDIUM

CVE-2023-41738
SynologySynology Router Manage...7.2HIGH

June 13

CVE-2023-2729
SynologyDiskStation Manager (DSM)7.5HIGH

CVE-2023-0142
SynologyDiskStation Manager (DSM)8.1HIGH

May 16

CVE-2023-32955
SynologySynology Router Manage...8.1HIGH

CVE-2023-32956
SynologySynology Router Manage...9.8CRITICAL

January 5

CVE-2023-0077
SynologySynology Router Manage...6.5MEDIUM

CVE-2022-43932
SynologySynology Router Manage...7.5HIGH

January 3

CVE-2022-43931
SynologyVpn Plus Server10CRITICAL

October 26

CVE-2022-43749
SynologyPresto File Server4.3MEDIUM

CVE-2022-43748
SynologyPresto File Server5.8MEDIUM

October 25

CVE-2022-27622
SynologyDiskstation Manager (dsm)4.1MEDIUM

CVE-2022-27623
SynologyDiskstation Manager (dsm)7.4HIGH

October 20

CVE-2022-3576
SynologyDiskstation Manager (dsm)5.3MEDIUM

CVE-2022-27624
SynologyDiskstation Manager (dsm)10CRITICAL

CVE-2022-27625
SynologyDiskstation Manager (dsm)10CRITICAL

CVE-2022-27626
SynologyDiskstation Manager (dsm)10CRITICAL

August 3

CVE-2022-27621
SynologyUsb Copy5.5MEDIUM

CVE-2022-27617
SynologySynology Calendar5MEDIUM

CVE-2022-27618
SynologyStorage Analyzer6.8MEDIUM

CVE-2022-27620
SynologySso Server6.8MEDIUM

CVE-2022-27619
SynologySynology Note Station ...6.8MEDIUM

CVE-2022-27616
SynologyDiskstation Manager (dsm)7.2HIGH

July 28

CVE-2022-27611
SynologyAudio Station5.4MEDIUM

CVE-2022-27614
SynologyMedia Server5.3MEDIUM

CVE-2022-27612
SynologyAudio Station7.3HIGH

CVE-2022-27613
SynologyCarddav Server8.3HIGH

CVE-2022-22684
SynologyDiskstation Manager (dsm)7.2HIGH

CVE-2022-22683
SynologyMedia Server10CRITICAL

CVE-2022-22685
SynologyWebdav Server8.7HIGH

CVE-2022-27615
SynologyDns Server7.7HIGH

July 26

CVE-2022-22686
SynologySynology Calendar6.5MEDIUM

July 25

CVE-2022-27610
SynologyDiskstation Manager (dsm)6.5MEDIUM

July 12

CVE-2022-22682
SynologySynology Calendar6.5MEDIUM

July 6

CVE-2022-22681
SynologyPhoto Station8.1HIGH

March 25

CVE-2022-22688
SynologyDiskstation Manager (dsm)8.8HIGH

March 21

CVE-2022-22687
SynologyDiskstation Manager (dsm)9.8CRITICAL

February 7

CVE-2021-43928
SynologyMail Station9.9CRITICAL

CVE-2021-43929
SynologyDiskstation Manager (dsm)6.5MEDIUM

CVE-2021-43926
SynologyDiskstation Manager (dsm)4.7MEDIUM

CVE-2022-22679
SynologyDiskstation Manager (dsm)6.5MEDIUM

CVE-2021-43925
SynologyDiskstation Manager (dsm)4.7MEDIUM

CVE-2021-43927
SynologyDiskstation Manager (dsm)4.7MEDIUM

CVE-2022-22680
SynologyDiskstation Manager (dsm)5.3MEDIUM

June 23

CVE-2021-29085
SynologyDiskstation Manager (dsm)8.6HIGH

CVE-2021-29087
SynologyDiskstation Manager (dsm)7.5HIGH

CVE-2021-29084
SynologyDiskstation Manager (dsm)7.5HIGH

CVE-2021-27649
SynologyDiskstation Manager (dsm)9.8CRITICAL

CVE-2021-29086
SynologyDiskstation Manager (dsm)5.3MEDIUM

June 18

CVE-2021-34811
SynologyDownload Station5MEDIUM

CVE-2021-34808
SynologyMedia Server5.8MEDIUM

CVE-2021-34810
SynologyDownload Station9.9CRITICAL

CVE-2021-34809
SynologyDownload Station9.9CRITICAL

CVE-2021-34812
SynologySynology Calendar5.8MEDIUM

June 2

CVE-2021-29091
SynologySynology Photo Station7.7HIGH

CVE-2021-29090
SynologySynology Photo Station7.2HIGH

CVE-2021-29089
SynologySynology Photo Station9.8CRITICAL

June 1

CVE-2021-29092
SynologySynology Photo Station8.8HIGH

CVE-2021-33184
SynologySynology Download Station7.7HIGH

CVE-2021-33181
SynologySynology Video Station6.6MEDIUM