7.5

CVSS3.1

CVE-2024-50631 -

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in the system syncing daemon in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to inject SQL commands, limited to write operations, via unsp…

πŸ“… Published: March 19, 2025, 5:50 a.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:26 p.m.

7.5

CVSS3.1

CVE-2024-50630 -

Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to obtain administrator credentials via unspecified vectors.

πŸ“… Published: March 19, 2025, 5:50 a.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:29 p.m.

5.3

CVSS3.1

CVE-2024-50629 -

Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to read limited files via unspecified vecto…

πŸ“… Published: March 19, 2025, 5:49 a.m. πŸ”„ Last Modified: Nov. 17, 2025, 1:38 p.m.

9.8

CVSS3.1

CVE-2024-12922 - Altair <= 5.2.4 - Unauthenticated Arbitrary Options Update via pp_import_current

The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check within functions.php in all versions up to, and including, 5.2.4. This makes it possible for unauthenticated attackers to update arbitrary option…

πŸ“… Published: March 19, 2025, 5:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-12295 - BoomBox Theme Extensions <= 1.8.0 - Authenticated (Subscriber+) Privilege Escalation via Password R…

The BoomBox Theme Extensions plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.8.0. This is due to the plugin not properly validating a user's identity prior to updating their password through the 'boombox_ajax_reset_password' fu…

πŸ“… Published: March 19, 2025, 4:21 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-2290 - LifterLMS <= 8.0.1 - Missing Authorization to Unauthenticated Post Trashing

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Unauthenticated Post Trashing due to a missing capability check on the delete_access_plan function and the related AJAX calls in all versions up to, and including, 8.0.1. This makes it possible for…

πŸ“… Published: March 19, 2025, 4:21 a.m. πŸ”„ Last Modified: April 21, 2026, 10 p.m.

9.8

CVSS3.1

CVE-2024-11131 -

A vulnerability regarding out-of-bounds read is found in the video interface. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camera Firmware versions before 1.2.0-0525 may be affected: BC500, CC400W and TC500.

πŸ“… Published: March 19, 2025, 2:15 a.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:40 p.m.

10

CVSS3.1

CVE-2024-10442 -

Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code, potentially leading to a broader impact across the…

πŸ“… Published: March 19, 2025, 2:14 a.m. πŸ”„ Last Modified: Jan. 16, 2026, 4:50 p.m.

4.3

CVSS3.1

CVE-2024-10445 -

Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to write limited files via unspe…

πŸ“… Published: March 19, 2025, 2:10 a.m. πŸ”„ Last Modified: Nov. 17, 2025, 1:42 p.m.

9.8

CVSS3.1

CVE-2024-10441 -

Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allows remote attackers to execute arbitrary code via unspecified vectors.

πŸ“… Published: March 19, 2025, 2:09 a.m. πŸ”„ Last Modified: Nov. 17, 2025, 1:43 p.m.
Total resulsts: 347773
Page 6166 of 34,778
Β« previous page Β» next page
Filters