Known Vulnerabilities for Contacts by Synology
Listed below are 1 of the newest known vulnerabilities associated with "Contacts" by "Synology".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-87605 json | Missing authorization in Contacts in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the r... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-81706 json | openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allo... | Not Provided | 2026-08-27 | 2026-08-27 |
| CVE-2026-73524 json | Cypht before 2.12.2 contains a cross-site scripting vulnerability in the contacts module that allows remote attackers to exec... | Not Provided | 2026-09-01 | 2026-09-04 |
| CVE-2026-72718 json | goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system `git... | Not Provided | 2026-08-10 | 2026-08-10 |
| CVE-2026-64746 json | An authorization issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.... | Not Provided | 2026-07-27 | 2026-08-17 |
| CVE-2026-64745 json | This issue was addressed with additional restrictions on the lock screen. This issue is fixed in macOS Sequoia 15.7.8, macOS ... | Not Provided | 2026-07-27 | 2026-07-28 |
| CVE-2026-64274 json | In the Linux kernel, the following vulnerability has been resolved: Input: goodix - clamp the device-reported contact count ... | Not Provided | 2026-07-25 | 2026-08-17 |
| CVE-2026-61909 json | An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV us... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-56547 json | The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler requi... | Not Provided | 2026-08-26 | 2026-08-26 |
| CVE-2026-53857 json | OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata could ... | Not Provided | 2026-06-16 | 2026-06-18 |