Vulnerabilities > Synology

DATE CVE VULNERABILITY TITLE RISK
2022-07-28 CVE-2022-22683 Classic Buffer Overflow vulnerability in Synology Media Server
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allows remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
synology CWE-120
critical
9.8
2022-07-28 CVE-2022-22684 OS Command Injection vulnerability in Synology Diskstation Manager
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in task management component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
network
low complexity
synology CWE-78
8.8
2022-07-28 CVE-2022-22685 Path Traversal vulnerability in Synology Webdav Server
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology WebDAV Server before 2.4.0-0062 allows remote authenticated users to delete arbitrary files via unspecified vectors.
network
low complexity
synology CWE-22
8.1
2022-07-28 CVE-2022-27612 Classic Buffer Overflow vulnerability in Synology Audio Station
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Audio Station before 6.5.4-3367 allows remote attackers to execute arbitrary commands via unspecified vectors.
network
low complexity
synology CWE-120
critical
9.8
2022-07-28 CVE-2022-27613 SQL Injection vulnerability in Synology Carddav Server
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in webapi component in Synology CardDAV Server before 6.0.10-0153 allows remote authenticated users to inject SQL commands via unspecified vectors.
network
low complexity
synology CWE-89
8.8
2022-07-28 CVE-2022-27614 Information Exposure vulnerability in Synology Media Server
Exposure of sensitive information to an unauthorized actor vulnerability in web server in Synology Media Server before 1.8.1-2876 allows remote attackers to obtain sensitive information via unspecified vectors.
network
low complexity
synology CWE-200
7.5
2022-07-28 CVE-2022-27615 Path Traversal vulnerability in Synology DNS Server
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology DNS Server before 2.2.2-5027 allows remote authenticated users to delete arbitrary files via unspecified vectors.
network
low complexity
synology CWE-22
8.1
2022-07-27 CVE-2022-27610 Path Traversal vulnerability in Synology Diskstation Manager
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25423 allows remote authenticated users to delete arbitrary files via unspecified vectors.
network
low complexity
synology CWE-22
8.1
2022-07-26 CVE-2022-22686 Cross-Site Request Forgery (CSRF) vulnerability in Synology Calendar
Cross-Site Request Forgery (CSRF) vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to hijack the authentication of administrators via unspecified vectors.
network
low complexity
synology CWE-352
8.0
2022-07-12 CVE-2022-22682 Cross-site Scripting vulnerability in Synology Calendar
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Event Management in Synology Calendar before 2.4.5-10930 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
synology CWE-79
5.4