CVE-2025-29846
- EPSS 0.06%
- Veröffentlicht 04.12.2025 15:15:56
- Zuletzt bearbeitet 05.12.2025 21:42:12
A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.
CVE-2025-29845
- EPSS 0.03%
- Veröffentlicht 04.12.2025 15:15:56
- Zuletzt bearbeitet 05.12.2025 21:43:11
A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.
CVE-2025-29844
- EPSS 0.03%
- Veröffentlicht 04.12.2025 15:15:56
- Zuletzt bearbeitet 05.12.2025 21:43:26
A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.
CVE-2025-29843
- EPSS 0.03%
- Veröffentlicht 04.12.2025 15:00:14
- Zuletzt bearbeitet 05.12.2025 21:43:34
A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.
CVE-2024-53288
- EPSS 0.14%
- Veröffentlicht 23.07.2025 04:11:58
- Zuletzt bearbeitet 29.07.2025 19:33:22
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in NTP Region functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to in...
CVE-2024-53287
- EPSS 0.14%
- Veröffentlicht 23.07.2025 04:11:51
- Zuletzt bearbeitet 29.07.2025 19:33:38
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to i...
CVE-2024-53286
- EPSS 0.42%
- Veröffentlicht 23.07.2025 04:11:30
- Zuletzt bearbeitet 29.07.2025 19:34:07
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privilege...
CVE-2024-53284
- EPSS 0.15%
- Veröffentlicht 09.12.2024 04:15:05
- Zuletzt bearbeitet 04.08.2025 19:07:30
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privil...
CVE-2024-53285
- EPSS 0.15%
- Veröffentlicht 09.12.2024 04:15:05
- Zuletzt bearbeitet 04.08.2025 19:07:26
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to r...
CVE-2024-53283
- EPSS 0.15%
- Veröffentlicht 09.12.2024 04:15:05
- Zuletzt bearbeitet 04.08.2025 19:07:37
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Router Port Forward functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privile...