CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2026-42731

    Last Modified: 30 May 2026

    Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through <= 5.4.9.

    Published: 27 May 2026
    4.8
    Medium

    CVE-2026-2288

    Last Modified: 30 May 2026

    The myLinksDump plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_title' parameter in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 27 May 2026
    6.1
    Medium

    CVE-2026-3349

    Last Modified: 27 May 2026

    The MinhNhut Link Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter on the redirect page in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 27 May 2026
    4.4
    Medium

    CVE-2026-3348

    Last Modified: 27 May 2026

    The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings (Description, Title, and other fields) in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the redirect page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 27 May 2026
    4.8
    Medium

    CVE-2026-2280

    Last Modified: 27 May 2026

    The rexCrawler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 27 May 2026
    6.5
    Medium

    CVE-2025-0898

    Last Modified: 30 May 2026

    The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 1.4.7 via the Draw SVG widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

    Published: 27 May 2026
    8
    High

    CVE-2026-3012

    Last Modified: 10 Sept 2026

    A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.

    Published: 27 May 2026
    9.3
    Critical

    CVE-2026-48906

    Last Modified: 1 Jun 2026

    The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.

    Published: 27 May 2026
    6.5
    Medium

    CVE-2026-48968

    Last Modified: 27 May 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slider allows DOM-Based XSS. This issue affects Master Slider: from n/a through 3.10.8.

    Published: 27 May 2026
    6.5
    Medium

    CVE-2026-48877

    Last Modified: 29 May 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Tom GenerateBlocks allows Retrieve Embedded Sensitive Data. This issue affects GenerateBlocks: from n/a through 2.1.0.

    Published: 27 May 2026
    6.2
    Medium

    CVE-2026-2237

    Last Modified: 2 Jun 2026

    A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information.

    Published: 27 May 2026
    6.1
    Medium

    CVE-2025-66593

    Last Modified: 2 Jun 2026

    An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.

    Published: 27 May 2026
    6.1
    Medium

    CVE-2025-66592

    Last Modified: 2 Jun 2026

    An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.

    Published: 27 May 2026
    8.6
    High

    CVE-2025-30028

    Last Modified: 2 Jun 2026

    A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.

    Published: 27 May 2026
    7.1
    High

    CVE-2025-52747

    Last Modified: 29 May 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jthemes Themebox - Digital Products Ecommerce allows Reflected XSS. This issue affects Themebox - Digital Products Ecommerce: from n/a through 1.4.2.

    Published: 27 May 2026
    7.5
    High

    CVE-2025-14713

    Last Modified: 2 Jun 2026

    An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server.

    Published: 27 May 2026
    6.1
    Medium

    CVE-2025-13593

    Last Modified: 2 Jun 2026

    Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.

    Published: 27 May 2026
    9.8
    Critical

    CVE-2025-12686

    Last Modified: 18 Jun 2026

    Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 27 May 2026
    8.1
    High

    CVE-2025-13392

    Last Modified: 2 Jun 2026

    Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN).

    Published: 27 May 2026
    7.1
    High

    CVE-2025-22741

    Last Modified: 29 May 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RiceTheme Felan Framework allows Reflected XSS. This issue affects Felan Framework: from n/a through 1.1.3.

    Published: 27 May 2026
    5.4
    Medium

    CVE-2025-13167

    Last Modified: 29 May 2026

    Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors.

    Published: 27 May 2026
    5.9
    Medium

    CVE-2025-10466

    Last Modified: 2 Jun 2026

    Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Synology Safe Access before 1.3.1-0329 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information or conduct limited denial-of-service in SRM.

    Published: 27 May 2026
    2.7
    Low

    CVE-2024-47272

    Last Modified: 28 May 2026

    Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors.

    Published: 27 May 2026
    4.9
    Medium

    CVE-2024-47271

    Last Modified: 28 May 2026

    Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.

    Published: 27 May 2026
    2.7
    Low

    CVE-2024-47270

    Last Modified: 28 May 2026

    Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors.

    Published: 27 May 2026
    4.9
    Medium

    CVE-2024-47269

    Last Modified: 28 May 2026

    Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.

    Published: 27 May 2026
    4.9
    Medium

    CVE-2024-47268

    Last Modified: 28 May 2026

    Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.

    Published: 27 May 2026
    2.7
    Low

    CVE-2024-47267

    Last Modified: 28 May 2026

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors.

    Published: 27 May 2026
    6.8
    Medium

    CVE-2024-11399

    Last Modified: 2 Jun 2026

    Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to conduct denial-of-service attacks via unspecified vectors.

    Published: 27 May 2026
    7.8
    High

    CVE-2023-52945

    Last Modified: 29 May 2026

    Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to execute arbitrary code via unspecified vectors.

    Published: 27 May 2026
    9.1
    Critical

    CVE-2026-49002

    Last Modified: 27 May 2026

    Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system data beyond their permissions, such as viewing and modifying configuration information.

    Published: 27 May 2026
    7.2
    High

    CVE-2026-40852

    Last Modified: 27 May 2026

    A highly authenticated attacker can alter the config generator injecting a payload into future created configurations. The device is not correctly checking this configuration value before passing it to an system execute leading to code execution. This can result in a total loss of confidentiality, integrity and availability.

    Published: 27 May 2026
    8.4
    High

    CVE-2026-40851

    Last Modified: 27 May 2026

    A local attacker can perform a confusion attack on the cfgparser via a specially crafted file on an USB stick leading to code execution. This can result in a total loss of confidentiality, integrity and availability.

    Published: 27 May 2026
    8.7
    High

    CVE-2026-40850

    Last Modified: 27 May 2026

    An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountData function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

    Published: 27 May 2026
    7.1
    High

    CVE-2026-40849

    Last Modified: 27 May 2026

    An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the user_alarmprofile view due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

    Published: 27 May 2026
    7.1
    High

    CVE-2026-40848

    Last Modified: 27 May 2026

    An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the tag view due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

    Published: 27 May 2026
    7.1
    High

    CVE-2026-40847

    Last Modified: 27 May 2026

    An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system_tag view due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

    Published: 27 May 2026
    7.1
    High

    CVE-2026-40846

    Last Modified: 27 May 2026

    An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system view due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

    Published: 27 May 2026
    7.1
    High

    CVE-2026-40845

    Last Modified: 27 May 2026

    An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the devices_configuration view due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

    Published: 27 May 2026
    7.1
    High

    CVE-2026-40844

    Last Modified: 27 May 2026

    An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dashboard view due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

    Published: 27 May 2026
    7.1
    High

    CVE-2026-40843

    Last Modified: 27 May 2026

    An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the alarming view due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

    Published: 27 May 2026
    7.1
    High

    CVE-2026-40842

    Last Modified: 27 May 2026

    An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getWidgetTags function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

    Published: 27 May 2026
    7.1
    High

    CVE-2026-40841

    Last Modified: 27 May 2026

    An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectTags function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

    Published: 27 May 2026
    7.1
    High

    CVE-2026-40840

    Last Modified: 27 May 2026

    An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the VerifyCreateLicences function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

    Published: 27 May 2026
    7.1
    High

    CVE-2026-40839

    Last Modified: 27 May 2026

    An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getComponentScalings function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

    Published: 27 May 2026
    7.1
    High

    CVE-2026-40838

    Last Modified: 27 May 2026

    An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getDeviceScalings function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

    Published: 27 May 2026
    7.1
    High

    CVE-2026-40837

    Last Modified: 27 May 2026

    An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectScalings function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

    Published: 27 May 2026
    7.1
    High

    CVE-2026-40836

    Last Modified: 27 May 2026

    An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the inmessage model due to improper neutralization of special elements in a SQL DELETE command allowing for reading the whole database and deleting entries in a non critical table. This can result in a total loss of confidentiality and some loss of integrity.

    Published: 27 May 2026
    7.1
    High

    CVE-2026-40835

    Last Modified: 27 May 2026

    An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the saveObjectFromData function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

    Published: 27 May 2026
    7.1
    High

    CVE-2026-40834

    Last Modified: 27 May 2026

    An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash_layout.php files saveDashboardLayout function due to improper neutralization of special elements in a SQL INSERT command allowing for reading the whole database and inserting entries into a non critical table. This can result in a total loss of confidentiality and some loss of integrity.

    Published: 27 May 2026