Known Vulnerabilities for Media Server by Synology
Listed below are 4 of the newest known vulnerabilities associated with "Media Server" by "Synology".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-34561 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization an... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2026-32275 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 1.3.10 to before version 2.17.0, ... | Not Provided | 2026-03-30 | 2026-04-01 |
| CVE-2026-31831 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/image... | Not Provided | 2026-03-30 | 2026-03-31 |
| CVE-2026-31804 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /pms_image_proxy ... | Not Provided | 2026-03-30 | 2026-04-01 |
| CVE-2026-31799 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 2.14.2 to before version 2.17.0 f... | Not Provided | 2026-03-30 | 2026-03-30 |
| CVE-2026-28505 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() functi... | Not Provided | 2026-03-30 | 2026-03-30 |
| CVE-2026-22742 | Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel... | Not Provided | 2026-03-27 | 2026-03-27 |
| CVE-2026-4984 | The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twilio-Signature'. When proce... | Not Provided | 2026-03-27 | 2026-03-27 |
| CVE-2025-49335 | Server-Side Request Forgery (SSRF) vulnerability in minnur External Media external-media allows Server Side Request Forgery.T... | Not Provided | 2026-01-07 | 2026-04-01 |
| CVE-2022-22683 | Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Media Serve... | 9.8 - CRITICAL | 2022-07-28 | 2022-08-03 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Synology | Media Server | 1.7.9-2858 | All | All | All |
| Application | Synology | Media Server | 1.7.8-2844 | All | All | All |
| Application | Synology | Media Server | 1.7.7-2855 | All | All | All |
| Application | Synology | Media Server | 1.7.6-2842 | All | All | All |
| Application | Synology | Media Server | 1.7.5-2854 | All | All | All |
| Application | Synology | Media Server | 1.7.4-2852 | All | All | All |
| Application | Synology | Media Server | 1.7.3-2841 | All | All | All |
| Application | Synology | Media Server | 1.7.2-2830 | All | All | All |
| Application | Synology | Media Server | 1.7.1-2820 | All | All | All |
| Application | Synology | Media Server | 1.7.1-2810 | All | All | All |
| Application | Synology | Media Server | 1.7.0-2810 | All | All | All |
| Application | Synology | Media Server | 1.7 | All | All | All |
| Application | Synology | Media Server | 1.6.2-2770 | All | All | All |
| Application | Synology | Media Server | 1.6.1-2767 | All | All | All |
| Application | Synology | Media Server | 1.6.0-2766 | All | All | All |
| Application | Synology | Media Server | 1.5-2762 | All | All | All |
| Application | Synology | Media Server | 1.4-2654 | All | All | All |
| Application | Synology | Media Server | 1.4-2653 | All | All | All |
| Application | Synology | Media Server | 1.4-2649 | All | All | All |
| Application | Synology | Media Server | 1.4-2644 | All | All | All |