Aggregating NVD, CVE, and multi-source threat feeds, this list provides deep analysis of high-risk threats such as RCE. By integrating CVSS and EPSS models, the system dynamically tracks Exp (Exploit) resources and PoC availability to accurately assess Exploitability. Combined with official Patches and remediation strategies, it helps prioritize Vulnerability Management workflows, significantly shortening response cycles and securing your critical assets.
Assigner (CNA / source):[email protected] Remove this filter
| CVE | Description | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|
| CVE-2024-47267 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors. | 2.7 | 0.33% | 2026-05-27 | 2026-06-17 |
| CVE-2024-11399 | Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to conduct denial-of-service attacks via unspecified vectors. | 6.8 | 0.11% | 2026-05-27 | 2026-06-17 |
| CVE-2023-52945 | Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to execute arbitrary code via unspecified vectors. | 7.8 | 0.14% | 2026-05-27 | 2026-06-17 |
| CVE-2021-47961 | A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined with user interaction. | 8.1 | 0.32% | 2026-04-10 | 2026-06-17 |
| CVE-2021-47960 | A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interface. By leveraging user interaction with a crafted web page, attackers may retrieve sensitive files such as configuration files, certificates, and logs, leading to information disclosure. | 6.5 | 0.19% | 2026-04-10 | 2026-06-17 |
| CVE-2026-3091 | An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files and conduct denial-of-service during installation by placing a malicious DLL in advance in the same directory as the installer. | 6.7 | 0.14% | 2026-02-23 | 2026-06-17 |
| CVE-2025-8074 | Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users to write arbitrary files with non-sensitive information via unspecified vectors. | 5.6 | 0.08% | 2025-12-04 | 2026-06-17 |
| CVE-2025-54160 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors. | 7.8 | 0.18% | 2025-12-04 | 2026-06-17 |
| CVE-2025-54159 | Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitrary files via unspecified vectors. | 7.5 | 0.37% | 2025-12-04 | 2026-06-17 |
| CVE-2025-54158 | Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors. | 7.8 | 0.17% | 2025-12-04 | 2026-06-17 |
| CVE-2025-2848 | A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical functions. | 6.3 | 0.38% | 2025-12-04 | 2026-06-17 |
| CVE-2025-29846 | A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages. | 7.2 | 0.60% | 2025-12-04 | 2026-06-17 |
| CVE-2025-29845 | A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files. | 4.3 | 0.41% | 2025-12-04 | 2026-06-17 |
| CVE-2025-29844 | A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information. | 4.3 | 0.41% | 2025-12-04 | 2026-06-17 |
| CVE-2025-29843 | A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files. | 5.4 | 0.36% | 2025-12-04 | 2026-06-17 |
| CVE-2024-5401 | Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before 7.1.1-42962-8 and 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote authenticated users to obtain privileges without consent via unspecified vectors. | 4.3 | 0.32% | 2025-12-04 | 2026-06-17 |
| CVE-2024-45539 | Out-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to conduct denial-of-service attacks via unspecified vectors. | 7.5 | 0.40% | 2025-12-04 | 2026-06-17 |
| CVE-2024-45538 | Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code via unspecified vectors. | 9.6 | 0.30% | 2025-12-04 | 2026-06-17 |
| CVE-2024-13987 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Synology RADIUS Server allows remote authenticated users with administrator privileges to read or write limited files in SRM and conduct limited denial-of-service via unspecified vectors. | 5.9 | 0.26% | 2025-08-29 | 2026-06-17 |
| CVE-2024-53288 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in NTP Region functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors. | 5.9 | 0.20% | 2025-07-23 | 2026-06-17 |