Known Vulnerabilities for Drive by Synology
Listed below are 4 of the newest known vulnerabilities associated with "Drive" by "Synology".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-49754 json | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 serv... | Not Provided | 2026-06-02 | 2026-06-02 |
| CVE-2026-46124 json | In the Linux kernel, the following vulnerability has been resolved: isofs: validate block number from NFS file handle in iso... | Not Provided | 2026-05-28 | 2026-06-01 |
| CVE-2026-46105 json | In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Limit NVMe request size to 2 MiB The HBA... | Not Provided | 2026-05-28 | 2026-05-30 |
| CVE-2026-45919 json | In the Linux kernel, the following vulnerability has been resolved: sched/rt: Skip currently executing CPU in rto_next_cpu()... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-45915 json | In the Linux kernel, the following vulnerability has been resolved: fat: avoid parent link count underflow in rmdir Corrupt... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-45721 json | Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that resolves... | Not Provided | 2026-05-26 | 2026-05-26 |
| CVE-2026-45229 json | Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated atta... | Not Provided | 2026-05-13 | 2026-05-13 |
| CVE-2026-45228 json | Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the temp... | Not Provided | 2026-05-13 | 2026-05-13 |
| CVE-2026-43487 json | In the Linux kernel, the following vulnerability has been resolved: ata: libata-core: Disable LPM on ST1000DM010-2EP102 Acc... | Not Provided | 2026-05-13 | 2026-05-13 |
| CVE-2026-43017 json | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate mesh send advertising payload ... | Not Provided | 2026-05-01 | 2026-05-01 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Synology | Drive | 1.1.2-10562 | |||
| Application | Synology | Drive | 1.1.1-10551 | |||
| Application | Synology | Drive | 1.1.0-10544 | |||
| Application | Synology | Drive | 1.0.3-10281 | |||
| Application | Synology | Drive | 1.0.2-10275 | |||
| Application | Synology | Drive | 1.0.1-10253 | |||
| Application | Synology | Drive | 1.0.0-10240 |