Synology Inc.
First CVE: May 12, 2017Active for: 9 years
301
CVEs Published
More CVEs Published than 83% of tracked CNAs
30.1
Avg CVEs / Year
More Avg CVEs / Year than 77% of tracked CNAs
6.9
Avg CVSS Score
Higher Avg CVSS Score than 40% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Synology Inc. as a CNA, 100.0% affect products that Synology Inc. develops as a vendor.
100.0%
Self-reported: 301Third-party: 0
Of all the CVEs published that affect products developed by Synology Inc., 84.8% are self-published by Synology Inc. as a CNA.
84.8%
15.2%
Self-published: 301Published by other CNAs: 54
Trends Over Time
The number and severity of CVEs published by Synology Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 12, 2017
9 years ago
Most Recent CVE
Jun 3, 2026
51 days ago
Top CVEs
All CVEs published by Synology Inc. as a CNA, regardless of affected vendor or product.
301 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15889HIGH Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field. | Dec 4, 2017 | 8.8 | 83 | NO | YES |
CVE-2017-9554MEDIUM An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspeci | Jul 24, 2017 | 5.3 | 77 | NO | YES |
CVE-2024-10443CRITICAL Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1. | Nov 15, 2024 | 9.8 | 53 | NO | YES |
CVE-2017-11155HIGH An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to obtain sensitive system information via unspe | Aug 8, 2017 | 7.5 | 52 | NO | YES |
CVE-2016-10329CRITICAL Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell metacharacters in the crafted ' | May 12, 2017 | 9.8 | 51 | NO | NO |
CVE-2017-11153CRITICAL Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain administrator privileges via a c | Aug 8, 2017 | 9.8 | 49 | NO | YES |
CVE-2017-11151CRITICAL A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files without authentication via the lo | Aug 8, 2017 | 9.8 | 48 | NO | YES |
CVE-2017-11152HIGH Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to write arbitrary files via the path p | Aug 8, 2017 | 7.5 | 39 | NO | YES |
CVE-2025-12686CRITICAL Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute | May 27, 2026 | 9.8 | 38 | NO | NO |
CVE-2025-13392CRITICAL Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) | May 27, 2026 | 9.8 | 37 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA301 CVEs
48%
35%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local33 (11.0%)
Network266 (88.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (0.7%)
Attack Complexity
Low273 (90.7%)
High28 (9.3%)
Unknown0 (0.0%)
User Interaction
None238 (79.1%)
Unknown0 (0.0%)
Required63 (20.9%)
Privileges Required
Low132 (43.9%)
High47 (15.6%)
None122 (40.5%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (301 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
0.7% of CVEs· 85th percentile
Nuclei
1 CVE
0.3% of CVEs· 73rd percentile
ExploitDB
7 CVEs
2.3% of CVEs· 90th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Synology Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Synology Inc. as a CNA — matched by CVE ID, not by organization name.