Known Vulnerabilities for Directory Server by Synology
Listed below are 4 of the newest known vulnerabilities associated with "Directory Server" by "Synology".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-56446 json | MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Bec... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-55201 json | Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function that ... | Not Provided | 2026-06-17 | 2026-06-18 |
| CVE-2026-50234 json | Lyrion Music Server 9.2.0 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary fil... | Not Provided | 2026-06-05 | 2026-06-08 |
| CVE-2026-50233 json | Lyrion Music Server 9.2.0 contains an arbitrary directory listing vulnerability in its readdirectory query, exposed through b... | Not Provided | 2026-06-05 | 2026-06-05 |
| CVE-2026-50203 json | A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or comp... | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-50031 json | ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management... | Not Provided | 2026-06-03 | 2026-06-03 |
| CVE-2026-49954 json | Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authenticated admini... | Not Provided | 2026-06-15 | 2026-06-16 |
| CVE-2026-49241 json | The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4, the... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-49238 json | An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), whi... | Not Provided | 2026-05-28 | 2026-05-28 |
| CVE-2026-49009 json | Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal. | Not Provided | 2026-05-27 | 2026-05-28 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Synology | Directory Server | 4.4.5-0101 | |||
| Application | Synology | Directory Server | 4.4.5-0099 | |||
| Application | Synology | Directory Server | 4.4.5-0093 | |||
| Application | Synology | Directory Server | 4.4.5-0090 | |||
| Application | Synology | Directory Server | 4.4.5-0086 | |||
| Application | Synology | Directory Server | - |