CVE-2025-1021
- EPSS 0.06%
- Published 23.04.2025 02:49:45
- Last modified 23.04.2025 14:08:13
Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows remote attackers to read arbitrary files via unspecified vectors.
CVE-2024-50629
- EPSS 0.06%
- Published 19.03.2025 05:49:56
- Last modified 27.03.2025 09:15:14
Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote atta...
CVE-2024-10445
- EPSS 0.02%
- Published 19.03.2025 02:10:57
- Last modified 27.03.2025 09:15:14
Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow ...
CVE-2024-10441
- EPSS 0.3%
- Published 19.03.2025 02:09:56
- Last modified 27.03.2025 09:15:13
Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allows remote attackers to e...
CVE-2024-10444
- EPSS 0.04%
- Published 19.03.2025 02:07:02
- Last modified 19.03.2025 02:15:28
Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows man-in-the-middle attackers to hijack the authentication of administrators via unsp...
CVE-2010-3684
- EPSS 0.05%
- Published 29.09.2010 17:00:05
- Last modified 11.04.2025 00:51:21
The FTP authentication module in Synology Disk Station 2.x logs passwords to the web application interface in cases of incorrect login attempts, which allows local users to obtain sensitive information by reading a log, a different vulnerability than...
CVE-2010-2453
- EPSS 0.23%
- Published 29.09.2010 17:00:02
- Last modified 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in Synology Disk Station 2.x before DSM3.0-1337 allow remote attackers to inject arbitrary web script or HTML by connecting to the FTP server and providing a crafted (1) USER or (2) PASS command, wh...