Show filters
300 Total Results
Displaying 11-20 of 300
Sort by:
Attacker Value
Unknown

CVE-2024-53285

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2024-53284

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2024-53283

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Router Port Forward functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2024-53282

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect MAC Filter functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2024-53281

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Network WOL functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2024-53280

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in network center policy route functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2024-53279

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in file station functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2024-11398

Disclosure Date: December 04, 2024 (last updated December 21, 2024)
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality in Synology Router Manager (SRM) before 1.3.1-9346-9 allows remote authenticated users to delete arbitrary files via unspecified vectors.
0
Attacker Value
Unknown

CVE-2023-52944

Disclosure Date: December 04, 2024 (last updated December 21, 2024)
Incorrect authorization vulnerability in ActionRule webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to perform limited actions on the set action rules function via unspecified vectors.
0
Attacker Value
Unknown

CVE-2023-52943

Disclosure Date: December 04, 2024 (last updated December 21, 2024)
Incorrect authorization vulnerability in Alert.Setting webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to to perform limited actions on the alerting function via unspecified vectors.
0