Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Synology Inc.

First CVE: Sep 29, 2010Active for: 16 yearsTotal CVEs: 355
59.3
VTI Score
TOP TARGET

Synology Inc. operates a broadly deployed portfolio of network-attached storage, surveillance, and network management appliances that serve both consumer and enterprise environments, representing a large and widely embedded attack surface. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability. The exposure recurs across flagship products including DiskStation Manager, Surveillance Station, Photo Station, and Router Manager through a consistent set of web-application and system-command weakness classes: cross-site scripting, path traversal, SQL injection, OS command injection, and sensitive information exposure. These input-handling and access-control flaws reflect the web-facing management interfaces and integration points endemic to network appliances, and defenders should treat Synology appliance updates with high priority, particularly for internet-reachable instances. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
355
Total CVEs
More Total CVEs than 100% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.6%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Synology Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 29, 2010
15 years ago
Most Recent CVE
Jun 3, 2026
51 days ago

Self-Reporting Analysis

Of all the CVEs published by Synology Inc. as a CNA, 100.0% affect products that Synology Inc. develops as a vendor.

100.0%
Self-reported: 301 (100.0%)
Third-party: 0 (0.0%)

Of all the CVEs published that affect products developed by Synology Inc., 84.8% are self-published by Synology Inc. as a CNA.

84.8%
15.2%
Self-published: 301 (84.8%)
Other CNAs: 54 (15.2%)

Products(102 total)

Top CVEs

Signals from CVEs in this vendor scope (355 CVEs).

355 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-3156HIGH
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg
Jan 26, 20217.899YESYES
CVE-2020-1472CRITICAL
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protoc
Aug 17, 202010.099YESYES
CVE-2013-6955HIGH
webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 allows remote attackers to append data to
Jan 9, 201410.089NOYES
CVE-2017-14491CRITICAL
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
Oct 4, 20179.885NOYES
CVE-2018-1160CRITICAL
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attac
Dec 20, 20189.884NOYES
CVE-2017-5753MEDIUM
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side
Jan 4, 20185.683NOYES
CVE-2017-15889HIGH
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field.
Dec 4, 20178.883NOYES
CVE-2017-9554MEDIUM
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspeci
Jul 24, 20175.377NOYES
CVE-2021-44142HIGH
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileser
Feb 21, 20228.870NONO
CVE-2019-9515HIGH
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RF
Aug 13, 20197.566NONO
View all 355 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products355 CVEs
46%
37%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local40 (11.3%)
Network291 (82.0%)
Unknown18 (5.1%)
Physical0 (0.0%)
Adjacent Network6 (1.7%)
Attack Complexity
Low303 (85.4%)
High34 (9.6%)
Unknown18 (5.1%)
User Interaction
None273 (76.9%)
Unknown18 (5.1%)
Required64 (18.0%)
Privileges Required
Low146 (41.1%)
High47 (13.2%)
None144 (40.6%)
Unknown18 (5.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (355 CVEs).

CISA KEV
2 CVEs
0.6% of CVEs· 99th percentile
Metasploit
6 CVEs
1.7% of CVEs· 97th percentile
Nuclei
2 CVEs
0.6% of CVEs· 95th percentile
ExploitDB
18 CVEs
5.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Synology Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Synology Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Synology Inc.'s Products

View all 10 CNAs →

Top CWEs