Vulnerabilidades em Synology
294 resultadosCVE-2023-2729MEDIUMUse of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7.2-64561 alEPSS 0.9%CVE-2024-39352MEDIUMA vulnerability regarding incorrect authorization is found in the firmware upgrade functionality. This allows remote authenticated users witEPSS 0.9%CVE-2021-43926MEDIUMImproper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in SynoloEPSS 0.9%CVE-2021-43925MEDIUMImproper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in SynoloEPSS 0.9%CVE-2021-43927MEDIUMImproper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Security Management functionality in SEPSS 0.9%CVE-2022-22681HIGHSession fixation vulnerability in access control management in Synology Photo Station before 6.8.16-3506 allows remote attackers to bypass sEPSS 0.9%CVE-2017-16774MEDIUMCross-site scripting (XSS) vulnerability in SYNO.Core.PersonalNotification.Event in Synology DiskStation Manager (DSM) before 6.1.4-15217-3 EPSS 0.8%CVE-2020-27652HIGHAlgorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackEPSS 0.8%CVE-2020-27653HIGHAlgorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to sEPSS 0.8%CVE-2015-9103—Multiple cross-site scripting (XSS) vulnerabilities in Synology Note Station 1.1-0212 and earlier allow remote authenticated attackers to inEPSS 0.8%CVE-2015-9105—Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, and 1.6 before 1.6-0EPSS 0.8%CVE-2018-13293MEDIUMCross-site scripting (XSS) vulnerability in Control Panel SSO Settings in Synology DiskStation Manager (DSM) before 6.2.1-23824 allows remotEPSS 0.8%CVE-2019-11827MEDIUMCross-site scripting (XSS) vulnerability in SYNO.NoteStation.Shard in Synology Note Station before 2.5.3-0863 allows remote attackers to injEPSS 0.8%CVE-2018-8917MEDIUMCross-site scripting (XSS) vulnerability in info.cgi in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to injEPSS 0.8%CVE-2018-8915MEDIUMCross-site scripting (XSS) vulnerability in Notification Center in Synology Calendar before 2.1.1-0502 allows remote authenticated users to EPSS 0.8%CVE-2019-11825MEDIUMCross-site scripting (XSS) vulnerability in Event Editor in Synology Calendar before 2.3.0-0615 allows remote attackers to inject arbitrary EPSS 0.8%CVE-2018-8918MEDIUMCross-site scripting (XSS) vulnerability in info.cgi in Synology Router Manager (SRM) before 1.1.7-6941 allows remote attackers to inject arEPSS 0.8%CVE-2018-8924MEDIUMCross-site scripting (XSS) vulnerability in Title Tootip in Synology Office before 3.0.3-2143 allows remote authenticated users to inject arEPSS 0.8%CVE-2018-8910MEDIUMCross-site scripting (XSS) vulnerability in Attachment Preview in Synology Drive before 1.0.1-10253 allows remote authenticated users to injEPSS 0.8%CVE-2018-8928MEDIUMCross-site scripting (XSS) vulnerability in Address Book Editor in Synology CardDAV Server before 6.0.8-0086 allows remote authenticated useEPSS 0.8%