Known Vulnerabilities for Storage Manager by Synology

Listed below are 1 of the newest known vulnerabilities associated with "Storage Manager" by "Synology".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-103474 json yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated man... Not Provided 2026-09-30 2026-09-30
CVE-2026-100798 json Cryptography misuse in Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, ... Not Provided 2026-09-29 2026-10-01
CVE-2026-100759 json Uninitialized memory in the Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird ... Not Provided 2026-09-29 2026-10-01
CVE-2026-86864 json pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job//object request to the pg_dum... Not Provided 2026-09-17 2026-09-17
CVE-2026-86861 json pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path wit... Not Provided 2026-09-17 2026-09-17
CVE-2026-84283 json Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-storage t... Not Provided 2026-09-25 2026-09-25
CVE-2026-75136 json UpSignOn for Windows before 7.19.0 contains an insecure credential storage vulnerability that allows local attackers to retri... Not Provided 2026-09-02 2026-09-03
CVE-2026-70737 json Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: St... Not Provided 2026-08-18 2026-08-25
CVE-2026-68535 json Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5.2 did not invoke the block type controller's validate(... Not Provided 2026-09-11 2026-09-14
CVE-2026-62867 json Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.... Not Provided 2026-08-21 2026-08-21

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report