Synology Inc.

First CVE: May 12, 2017Active for: 9 years
301
CVEs Published
More CVEs Published than 83% of tracked CNAs
30.1
Avg CVEs / Year
More Avg CVEs / Year than 77% of tracked CNAs
6.9
Avg CVSS Score
Higher Avg CVSS Score than 40% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Synology Inc. as a CNA, 100.0% affect products that Synology Inc. develops as a vendor.

100.0%
Self-reported: 301Third-party: 0

Of all the CVEs published that affect products developed by Synology Inc., 84.8% are self-published by Synology Inc. as a CNA.

84.8%
15.2%
Self-published: 301Published by other CNAs: 54

Trends Over Time

The number and severity of CVEs published by Synology Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 12, 2017
9 years ago
Most Recent CVE
Jun 3, 2026
51 days ago

Top CVEs

All CVEs published by Synology Inc. as a CNA, regardless of affected vendor or product.

301 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field.
Dec 4, 20178.883NOYES
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspeci
Jul 24, 20175.377NOYES
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.
Nov 15, 20249.853NOYES
An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to obtain sensitive system information via unspe
Aug 8, 20177.552NOYES
Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell metacharacters in the crafted '
May 12, 20179.851NONO
Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain administrator privileges via a c
Aug 8, 20179.849NOYES
A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files without authentication via the lo
Aug 8, 20179.848NOYES
Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to write arbitrary files via the path p
Aug 8, 20177.539NOYES
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute
May 27, 20269.838NONO
Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected)
May 27, 20269.837NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA301 CVEs
Severity distribution among all CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local33 (11.0%)
Network266 (88.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (0.7%)
Attack Complexity
Low273 (90.7%)
High28 (9.3%)
Unknown0 (0.0%)
User Interaction
None238 (79.1%)
Unknown0 (0.0%)
Required63 (20.9%)
Privileges Required
Low132 (43.9%)
High47 (15.6%)
None122 (40.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (301 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
0.7% of CVEs· 85th percentile
Nuclei
1 CVE
0.3% of CVEs· 73rd percentile
ExploitDB
7 CVEs
2.3% of CVEs· 90th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Synology Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Synology Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs