- EPSS 0.35%
- Veröffentlicht 18.09.2026 08:25:51
- Zuletzt bearbeitet 18.09.2026 19:07:38
An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write arbitrary files ...
CVE-2026-13683
- EPSS 0.25%
- Veröffentlicht 18.09.2026 08:22:58
- Zuletzt bearbeitet 18.09.2026 19:07:38
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenti...
CVE-2026-13623
- EPSS 0.19%
- Veröffentlicht 18.09.2026 08:22:41
- Zuletzt bearbeitet 18.09.2026 19:07:38
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated use...
CVE-2026-13666
- EPSS 0.19%
- Veröffentlicht 18.09.2026 08:22:29
- Zuletzt bearbeitet 18.09.2026 20:17:07
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write limited fi...
CVE-2026-6205
- EPSS 0.32%
- Veröffentlicht 18.09.2026 08:22:15
- Zuletzt bearbeitet 18.09.2026 20:17:21
An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct denial...
CVE-2026-13673
- EPSS 0.31%
- Veröffentlicht 18.09.2026 08:22:00
- Zuletzt bearbeitet 18.09.2026 20:17:07
An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to read or write arbitrary fi...
CVE-2026-13635
- EPSS 0.27%
- Veröffentlicht 18.09.2026 08:21:42
- Zuletzt bearbeitet 18.09.2026 20:17:06
An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to obtain non-sensitive information.
CVE-2026-13639
- EPSS 0.51%
- Veröffentlicht 18.09.2026 08:21:27
- Zuletzt bearbeitet 18.09.2026 20:17:06
An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attack...
CVE-2026-13684
- EPSS 0.46%
- Veröffentlicht 18.09.2026 08:19:14
- Zuletzt bearbeitet 18.09.2026 20:17:08
An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-se...
CVE-2025-13392
- EPSS 0.53%
- Veröffentlicht 27.05.2026 08:36:06
- Zuletzt bearbeitet 07.10.2026 08:10:00
Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge...