Show filters
300 Total Results
Displaying 81-90 of 300
Sort by:
Attacker Value
Unknown
CVE-2022-27618
Disclosure Date: August 02, 2022 (last updated October 08, 2023)
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Storage Analyzer before 2.1.0-0390 allows remote authenticated users to delete arbitrary files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-27617
Disclosure Date: July 28, 2022 (last updated October 08, 2023)
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to download arbitrary files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-27616
Disclosure Date: July 28, 2022 (last updated January 15, 2025)
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 7.0.1-42218-3 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-22684
Disclosure Date: July 28, 2022 (last updated January 15, 2025)
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in task management component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-27615
Disclosure Date: July 27, 2022 (last updated October 08, 2023)
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology DNS Server before 2.2.2-5027 allows remote authenticated users to delete arbitrary files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-27614
Disclosure Date: July 27, 2022 (last updated October 08, 2023)
Exposure of sensitive information to an unauthorized actor vulnerability in web server in Synology Media Server before 1.8.1-2876 allows remote attackers to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-27613
Disclosure Date: July 25, 2022 (last updated October 08, 2023)
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in webapi component in Synology CardDAV Server before 6.0.10-0153 allows remote authenticated users to inject SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-27612
Disclosure Date: July 25, 2022 (last updated October 08, 2023)
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Audio Station before 6.5.4-3367 allows remote attackers to execute arbitrary commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-27611
Disclosure Date: July 25, 2022 (last updated October 08, 2023)
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Audio Station before 6.5.4-3367 allows remote authenticated users to delete arbitrary files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-27610
Disclosure Date: July 25, 2022 (last updated October 07, 2023)
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25423 allows remote authenticated users to delete arbitrary files via unspecified vectors.
0