Vulnerabilities > Synology > High

DATE CVE VULNERABILITY TITLE RISK
2022-10-20 CVE-2022-27626 Unspecified vulnerability in Synology Diskstation Manager
A vulnerability regarding concurrent execution using shared resource with improper synchronization ('Race Condition') is found in the session processing functionality of Out-of-Band (OOB) Management.
network
high complexity
synology
8.1
2022-10-20 CVE-2022-3576 Unspecified vulnerability in Synology Diskstation Manager
A vulnerability regarding out-of-bounds read is found in the session processing functionality of Out-of-Band (OOB) Management.
network
low complexity
synology
7.5
2022-08-03 CVE-2022-27616 Unspecified vulnerability in Synology Diskstation Manager
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 7.0.1-42218-3 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
network
low complexity
synology
7.2
2022-07-28 CVE-2022-27611 Unspecified vulnerability in Synology Audio Station
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Audio Station before 6.5.4-3367 allows remote authenticated users to delete arbitrary files via unspecified vectors.
network
low complexity
synology
8.1
2022-07-28 CVE-2022-22684 Unspecified vulnerability in Synology Diskstation Manager
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in task management component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
network
low complexity
synology
8.8
2022-07-28 CVE-2022-22685 Unspecified vulnerability in Synology Webdav Server
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology WebDAV Server before 2.4.0-0062 allows remote authenticated users to delete arbitrary files via unspecified vectors.
network
low complexity
synology
8.1
2022-07-28 CVE-2022-27613 Unspecified vulnerability in Synology Carddav Server
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in webapi component in Synology CardDAV Server before 6.0.10-0153 allows remote authenticated users to inject SQL commands via unspecified vectors.
network
low complexity
synology
8.8
2022-07-28 CVE-2022-27614 Unspecified vulnerability in Synology Media Server
Exposure of sensitive information to an unauthorized actor vulnerability in web server in Synology Media Server before 1.8.1-2876 allows remote attackers to obtain sensitive information via unspecified vectors.
network
low complexity
synology
7.5
2022-07-28 CVE-2022-27615 Unspecified vulnerability in Synology DNS Server
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology DNS Server before 2.2.2-5027 allows remote authenticated users to delete arbitrary files via unspecified vectors.
network
low complexity
synology
8.1
2022-07-27 CVE-2022-27610 Unspecified vulnerability in Synology Diskstation Manager
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25423 allows remote authenticated users to delete arbitrary files via unspecified vectors.
network
low complexity
synology
8.1