Vulnerabilities > Synology > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-03-25 CVE-2022-22687 Classic Buffer Overflow vulnerability in Synology products
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
synology CWE-120
critical
9.8
2022-02-07 CVE-2021-43925 SQL Injection vulnerability in Synology Diskstation Manager
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inject SQL commands via unspecified vectors.
network
low complexity
synology CWE-89
critical
9.8
2022-02-07 CVE-2021-43926 SQL Injection vulnerability in Synology Diskstation Manager
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inject SQL commands via unspecified vectors.
network
low complexity
synology CWE-89
critical
9.8
2022-02-07 CVE-2021-43927 SQL Injection vulnerability in Synology Diskstation Manager
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Security Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inject SQL commands via unspecified vectors.
network
low complexity
synology CWE-89
critical
9.8
2021-06-23 CVE-2021-27649 Unspecified vulnerability in Synology products
Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
synology
critical
9.8
2021-06-02 CVE-2021-29089 Unspecified vulnerability in Synology Photo Station
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in thumbnail component in Synology Photo Station before 6.8.14-3500 allows remote attackers users to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
synology
critical
9.8
2021-06-01 CVE-2021-33180 Unspecified vulnerability in Synology Media Server
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
synology
critical
9.8
2021-06-01 CVE-2021-33181 Unspecified vulnerability in Synology Video Station
Server-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station before 2.4.10-1632 allows remote authenticated users to send arbitrary request to intranet resources via unspecified vectors.
network
low complexity
synology
critical
9.1
2021-03-12 CVE-2021-27647 Out-of-bounds Read vulnerability in Synology Diskstation Manager
Out-of-bounds Read vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via crafted web requests.
network
low complexity
synology CWE-125
critical
9.8
2021-03-12 CVE-2021-27646 Use After Free vulnerability in Synology Diskstation Manager
Use After Free vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via crafted web requests.
network
low complexity
synology CWE-416
critical
9.8