7.8
CVE-2025-54160 -
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors.
7.5
CVE-2025-54159 -
Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitrary files via unspecified vectors.
7.8
CVE-2025-54158 -
Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors.
6.3
CVE-2025-2848 -
A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical functions.
5.1
CVE-2025-14008 - dayrui XunRuiCMS Project Domain Change Test admin79f2ec220c7e.php server-side request forgery
A flaw has been found in dayrui XunRuiCMS up to 4.7.1. This vulnerability affects unknown code of the file admin79f2ec220c7e.php?c=api&m=test_site_domain of the component Project Domain Change Test. This manipulation of the argument v causes server-side request forgery. It is possible to initiate tβ¦
7.2
CVE-2025-29846 -
A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.
4.3
CVE-2025-29845 -
A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.
4.3
CVE-2025-29844 -
A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.
5.4
CVE-2025-29843 -
A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.
2
CVE-2025-14007 - dayrui XunRuiCMS Domain Name Binding admin79f2ec220c7e.php cross site scripting
A vulnerability was detected in dayrui XunRuiCMS up to 4.7.1. This affects an unknown part of the file /admin79f2ec220c7e.php?c=api&m=demo&name=mobile of the component Domain Name Binding Page. The manipulation results in cross site scripting. The attack may be performed from remote. A high complexβ¦