CVE List – Find High-Risk & Exploited Vulnerabilities

Aggregating NVD, CVE, and multi-source threat feeds, this list provides deep analysis of high-risk threats such as RCE. By integrating CVSS and EPSS models, the system dynamically tracks Exp (Exploit) resources and PoC availability to accurately assess Exploitability. Combined with official Patches and remediation strategies, it helps prioritize Vulnerability Management workflows, significantly shortening response cycles and securing your critical assets.

Assigner (CNA / source):[email protected] Remove this filter

Showing 2140 of 307 results
«« First « Prev Page 2 / 16 Next »
CVE Description Max CVSS EPSS % Published Updated
CVE-2024-47267 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors. 2.7 0.33% 2026-05-27 2026-06-17
CVE-2024-11399 Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to conduct denial-of-service attacks via unspecified vectors. 6.8 0.11% 2026-05-27 2026-06-17
CVE-2023-52945 Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to execute arbitrary code via unspecified vectors. 7.8 0.14% 2026-05-27 2026-06-17
CVE-2021-47961 A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined with user interaction. 8.1 0.32% 2026-04-10 2026-06-17
CVE-2021-47960 A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interface. By leveraging user interaction with a crafted web page, attackers may retrieve sensitive files such as configuration files, certificates, and logs, leading to information disclosure. 6.5 0.19% 2026-04-10 2026-06-17
CVE-2026-3091 An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files and conduct denial-of-service during installation by placing a malicious DLL in advance in the same directory as the installer. 6.7 0.14% 2026-02-23 2026-06-17
CVE-2025-8074 Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users to write arbitrary files with non-sensitive information via unspecified vectors. 5.6 0.08% 2025-12-04 2026-06-17
CVE-2025-54160 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors. 7.8 0.18% 2025-12-04 2026-06-17
CVE-2025-54159 Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitrary files via unspecified vectors. 7.5 0.37% 2025-12-04 2026-06-17
CVE-2025-54158 Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors. 7.8 0.17% 2025-12-04 2026-06-17
CVE-2025-2848 A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical functions. 6.3 0.38% 2025-12-04 2026-06-17
CVE-2025-29846 A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages. 7.2 0.60% 2025-12-04 2026-06-17
CVE-2025-29845 A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files. 4.3 0.41% 2025-12-04 2026-06-17
CVE-2025-29844 A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information. 4.3 0.41% 2025-12-04 2026-06-17
CVE-2025-29843 A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files. 5.4 0.36% 2025-12-04 2026-06-17
CVE-2024-5401 Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before 7.1.1-42962-8 and 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote authenticated users to obtain privileges without consent via unspecified vectors. 4.3 0.32% 2025-12-04 2026-06-17
CVE-2024-45539 Out-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to conduct denial-of-service attacks via unspecified vectors. 7.5 0.40% 2025-12-04 2026-06-17
CVE-2024-45538 Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code via unspecified vectors. 9.6 0.30% 2025-12-04 2026-06-17
CVE-2024-13987 Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Synology RADIUS Server allows remote authenticated users with administrator privileges to read or write limited files in SRM and conduct limited denial-of-service via unspecified vectors. 5.9 0.26% 2025-08-29 2026-06-17
CVE-2024-53288 Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in NTP Region functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors. 5.9 0.20% 2025-07-23 2026-06-17
«« First « Prev Page 2 / 16 Next »
cvelogic Threat Intelligence