Show filters
24 Total Results
Displaying 1-10 of 24
Sort by:
Attacker Value
Unknown

CVE-2023-52944

Disclosure Date: December 04, 2024 (last updated December 21, 2024)
Incorrect authorization vulnerability in ActionRule webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to perform limited actions on the set action rules function via unspecified vectors.
0
Attacker Value
Unknown

CVE-2023-52943

Disclosure Date: December 04, 2024 (last updated December 21, 2024)
Incorrect authorization vulnerability in Alert.Setting webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to to perform limited actions on the alerting function via unspecified vectors.
0
Attacker Value
Unknown

CVE-2024-29241

Disclosure Date: March 28, 2024 (last updated January 15, 2025)
Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to bypass security constraints via unspecified vectors.
Attacker Value
Unknown

CVE-2024-29240

Disclosure Date: March 28, 2024 (last updated January 15, 2025)
Missing authorization vulnerability in LayoutSave webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to conduct denial-of-service attacks via unspecified vectors.
Attacker Value
Unknown

CVE-2024-29239

Disclosure Date: March 28, 2024 (last updated January 15, 2025)
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Recording.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to inject SQL commands via unspecified vectors.
Attacker Value
Unknown

CVE-2024-29238

Disclosure Date: March 28, 2024 (last updated January 15, 2025)
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to inject SQL commands via unspecified vectors.
Attacker Value
Unknown

CVE-2024-29237

Disclosure Date: March 28, 2024 (last updated January 15, 2025)
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in ActionRule.Delete webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to inject SQL commands via unspecified vectors.
Attacker Value
Unknown

CVE-2024-29236

Disclosure Date: March 28, 2024 (last updated January 15, 2025)
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in AudioPattern.Delete webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to inject SQL commands via unspecified vectors.
Attacker Value
Unknown

CVE-2024-29235

Disclosure Date: March 28, 2024 (last updated January 15, 2025)
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in IOModule.EnumLog webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to inject SQL commands via unspecified vectors.
Attacker Value
Unknown

CVE-2024-29234

Disclosure Date: March 28, 2024 (last updated January 15, 2025)
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to inject SQL commands via unspecified vectors.