Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · synology

synology

· 31 Critical

Total CVEs

337

Critical

31

Products

94

Search All CVEs →

337

Products (94)

diskstation manager132 CVEsrouter manager62 CVEsphoto station33 CVEsskynas29 CVEssurveillance station25 CVEsvs960hd firmware22 CVEsvs960hd22 CVEsdiskstation manager unified controller21 CVEsskynas firmware13 CVEscalendar11 CVEsbc500 firmware9 CVEstc5009 CVEsbc5009 CVEstc500 firmware9 CVEsdownload station8 CVEsuc32008 CVEsactive backup for business agent7 CVEsvideo station6 CVEsdrive server6 CVEsdrive client6 CVEsmedia server6 CVEsdns server5 CVEsbeedrive5 CVEsnote station5 CVEsssl vpn client5 CVEsbeestation os4 CVEsaudio station4 CVEsdirectory server4 CVEsds3622xs\+4 CVEsfs34104 CVEshd65004 CVEsradius server4 CVEsfile station3 CVEsoffice3 CVEschat3 CVEsvirtual diskstation manager3 CVEscarddav server3 CVEsmailplus server3 CVEsapplication service2 CVEsdsm2 CVEsdisk station ds710\+2 CVEspresto file server2 CVEsdisk station ds411\+2 CVEsdisk station ds110\+2 CVEsdisk station ds1092 CVEsdisk station ds1010\+2 CVEsdisk station ds210j2 CVEsdisk station ds409slim2 CVEsdisk station ds4102 CVEssafeaccess2 CVEsdisk station ds410j2 CVEsdisk station ds210\+2 CVEssso server2 CVEsmoments2 CVEsdisk station ds2092 CVEsdisk station ds110j2 CVEscloud station1 CVEscc400w firmware1 CVEscc400w1 CVEsstorage analyzer1 CVEssynology photo station1 CVEsbeephotos1 CVEsassistant1 CVEsunified controller1 CVEsuniversal search1 CVEsusb copy1 CVEsantivirus essential1 CVEsvpn plus server1 CVEsvs360hd1 CVEsvs360hd firmware1 CVEsvirtual machine manager1 CVEsdocker1 CVEsds1071 CVEsds107 firmware1 CVEsds1161 CVEsds116 firmware1 CVEsds2131 CVEsds213 firmware1 CVEsactive backup for microsoft 3651 CVEsds audio1 CVEsds file1 CVEsds photo\+1 CVEsactive backup for business recovery media creator1 CVEsweb station1 CVEsmail server1 CVEsmail station1 CVEscontacts1 CVEscloud station drive1 CVEscloud station backup1 CVEsphoto station uploader1 CVEsphotos1 CVEspresto client1 CVEswebdav server1 CVEsreplication service1 CVEs

Recent Vulnerabilities

View all 337
CVE-2022-49036HIGH 7.8

An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.

CVE-2025-13167MEDIUM 5.4

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors.

CVE-2024-47272LOW 2.7

Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors.

CVE-2024-47271MEDIUM 4.9

Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.

CVE-2024-47270LOW 2.7

Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors.

CVE-2024-47269MEDIUM 4.9

Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.

CVE-2024-47268MEDIUM 4.9

Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.

CVE-2024-47267LOW 2.7

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors.

CVE-2023-52945HIGH 7.8

Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to execute arbitrary code via unspecified vectors.

CVE-2021-47961HIGH 8.1

A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined with user interaction.

CVE-2021-47960MEDIUM 6.5

A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interface. By leveraging user interaction with a crafted web page, attackers may retrieve sensitive files such as configuration files, certificates, and logs, leading to information disclosure.

CVE-2026-3091MEDIUM 6.7

An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files during installation by placing a malicious DLL in advance in the same directory as the installer.

CVE-2025-8074MEDIUM 5.6

Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users to write arbitrary files with non-sensitive information via unspecified vectors.

CVE-2025-54160HIGH 7.8

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors.

CVE-2025-54159HIGH 7.5

Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitrary files via unspecified vectors.

CVE-2025-54158HIGH 7.8

Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors.

CVE-2025-2848MEDIUM 6.3

A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical functions.

CVE-2025-29846HIGH 7.2

A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.

CVE-2025-29845MEDIUM 4.3

A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.

CVE-2025-29844MEDIUM 4.3

A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.

CVE-2025-29843MEDIUM 5.4

A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.

CVE-2024-5401MEDIUM 4.3

Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before 7.1.1-42962-8 and 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote authenticated users to obtain privileges without consent via unspecified vectors.

CVE-2024-45539HIGH 7.5

Out-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to conduct denial-of-service attacks via unspecified vectors.

CVE-2024-45538CRITICAL 9.6

Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2024-53288MEDIUM 5.9

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in NTP Region functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors.