CVE 清單 – 發現高風險與在野利用漏洞

聚合 NVD、CVE 及多源情資,深度解析 RCE 等高危風險。系統整合 CVSS 與 EPSS 模型,動態追蹤 Exploit 資源與 PoC 公開狀態,研判可利用性。結合官方修補與修復方案,優化漏洞管理優先級,縮短回應週期,保障資產安全。

指派機構(CNA / 來源):[email protected] 移除此篩選

顯示 120307 筆結果
«« 第一頁 « 上一頁 第 1 / 16 頁 下一頁 »
CVE 描述 最高 CVSS EPSS % 公開時間 更新時間
CVE-2026-3091 An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files and conduct denial-of-service during installation by placing a malicious DLL in advance in the same directory as the installer. 6.7 0.14% 2026-02-23 2026-06-17
CVE-2026-2237 A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information. 6.2 0.09% 2026-05-27 2026-06-17
CVE-2025-8074 Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users to write arbitrary files with non-sensitive information via unspecified vectors. 5.6 0.08% 2025-12-04 2026-06-17
CVE-2025-66593 An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. 6.1 0.09% 2026-05-27 2026-06-17
CVE-2025-66592 An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. 6.1 0.09% 2026-05-27 2026-06-17
CVE-2025-54160 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors. 7.8 0.18% 2025-12-04 2026-06-17
CVE-2025-54159 Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitrary files via unspecified vectors. 7.5 0.37% 2025-12-04 2026-06-17
CVE-2025-54158 Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors. 7.8 0.17% 2025-12-04 2026-06-17
CVE-2025-4679 A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive information via unspecified vectors. 6.5 1.08% 2025-05-16 2026-06-17
CVE-2025-30028 A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files. 8.6 0.37% 2026-05-27 2026-06-17
CVE-2025-2848 A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical functions. 6.3 0.38% 2025-12-04 2026-06-17
CVE-2025-29846 A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages. 7.2 0.60% 2025-12-04 2026-06-17
CVE-2025-29845 A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files. 4.3 0.41% 2025-12-04 2026-06-17
CVE-2025-29844 A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information. 4.3 0.41% 2025-12-04 2026-06-17
CVE-2025-29843 A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files. 5.4 0.36% 2025-12-04 2026-06-17
CVE-2025-1021 Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows remote attackers to read arbitrary files via unspecified vectors. 7.5 0.47% 2025-04-22 2026-06-17
CVE-2025-14713 An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server. 7.5 0.47% 2026-05-27 2026-06-17
CVE-2025-13593 Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. 6.1 0.09% 2026-05-27 2026-06-17
CVE-2025-13392 Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN). 8.1 0.52% 2026-05-27 2026-06-17
CVE-2025-13167 Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors. 5.4 0.25% 2026-05-27 2026-06-17
«« 第一頁 « 上一頁 第 1 / 16 頁 下一頁 »
cvelogic Threat Intelligence