Show filters
300 Total Results
Displaying 91-100 of 300
Sort by:
Attacker Value
Unknown
CVE-2022-22686
Disclosure Date: July 25, 2022 (last updated October 07, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to hijack the authentication of administrators via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-22685
Disclosure Date: July 25, 2022 (last updated October 08, 2023)
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology WebDAV Server before 2.4.0-0062 allows remote authenticated users to delete arbitrary files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-22683
Disclosure Date: July 25, 2022 (last updated October 08, 2023)
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allows remote attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-22682
Disclosure Date: July 11, 2022 (last updated October 07, 2023)
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Event Management in Synology Calendar before 2.4.5-10930 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-22681
Disclosure Date: July 04, 2022 (last updated October 07, 2023)
Session fixation vulnerability in access control management in Synology Photo Station before 6.8.16-3506 allows remote attackers to bypass security constraint via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-22688
Disclosure Date: March 21, 2022 (last updated February 23, 2025)
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-2 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-22687
Disclosure Date: March 21, 2022 (last updated February 23, 2025)
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-22680
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
Exposure of sensitive information to an unauthorized actor vulnerability in Web Server in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2021-43928
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in mail sending and receiving component in Synology Mail Station before 20211105-10315 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2021-43927
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Security Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inject SQL commands via unspecified vectors.
0