聚合 NVD、CVE 及多源情資,深度解析 RCE 等高危風險。系統整合 CVSS 與 EPSS 模型,動態追蹤 Exploit 資源與 PoC 公開狀態,研判可利用性。結合官方修補與修復方案,優化漏洞管理優先級,縮短回應週期,保障資產安全。
指派機構(CNA / 來源):[email protected] 移除此篩選
| CVE | 描述 | 最高 CVSS | EPSS % | 公開時間 | 更新時間 |
|---|---|---|---|---|---|
| CVE-2026-3091 | An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files and conduct denial-of-service during installation by placing a malicious DLL in advance in the same directory as the installer. | 6.7 | 0.14% | 2026-02-23 | 2026-06-17 |
| CVE-2026-2237 | A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information. | 6.2 | 0.09% | 2026-05-27 | 2026-06-17 |
| CVE-2025-8074 | Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users to write arbitrary files with non-sensitive information via unspecified vectors. | 5.6 | 0.08% | 2025-12-04 | 2026-06-17 |
| CVE-2025-66593 | An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. | 6.1 | 0.09% | 2026-05-27 | 2026-06-17 |
| CVE-2025-66592 | An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. | 6.1 | 0.09% | 2026-05-27 | 2026-06-17 |
| CVE-2025-54160 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors. | 7.8 | 0.18% | 2025-12-04 | 2026-06-17 |
| CVE-2025-54159 | Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitrary files via unspecified vectors. | 7.5 | 0.37% | 2025-12-04 | 2026-06-17 |
| CVE-2025-54158 | Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors. | 7.8 | 0.17% | 2025-12-04 | 2026-06-17 |
| CVE-2025-4679 | A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive information via unspecified vectors. | 6.5 | 1.08% | 2025-05-16 | 2026-06-17 |
| CVE-2025-30028 | A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files. | 8.6 | 0.37% | 2026-05-27 | 2026-06-17 |
| CVE-2025-2848 | A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical functions. | 6.3 | 0.38% | 2025-12-04 | 2026-06-17 |
| CVE-2025-29846 | A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages. | 7.2 | 0.60% | 2025-12-04 | 2026-06-17 |
| CVE-2025-29845 | A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files. | 4.3 | 0.41% | 2025-12-04 | 2026-06-17 |
| CVE-2025-29844 | A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information. | 4.3 | 0.41% | 2025-12-04 | 2026-06-17 |
| CVE-2025-29843 | A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files. | 5.4 | 0.36% | 2025-12-04 | 2026-06-17 |
| CVE-2025-1021 | Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows remote attackers to read arbitrary files via unspecified vectors. | 7.5 | 0.47% | 2025-04-22 | 2026-06-17 |
| CVE-2025-14713 | An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server. | 7.5 | 0.47% | 2026-05-27 | 2026-06-17 |
| CVE-2025-13593 | Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. | 6.1 | 0.09% | 2026-05-27 | 2026-06-17 |
| CVE-2025-13392 | Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN). | 8.1 | 0.52% | 2026-05-27 | 2026-06-17 |
| CVE-2025-13167 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors. | 5.4 | 0.25% | 2026-05-27 | 2026-06-17 |