Known Vulnerabilities for Storage Manager by Synology
Listed below are 1 of the newest known vulnerabilities associated with "Storage Manager" by "Synology".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-103474 json | yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated man... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-100798 json | Cryptography misuse in Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, ... | Not Provided | 2026-09-29 | 2026-10-01 |
| CVE-2026-100759 json | Uninitialized memory in the Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird ... | Not Provided | 2026-09-29 | 2026-10-01 |
| CVE-2026-86864 json | pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/ |
Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-86861 json | pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path wit... | Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-84283 json | Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-storage t... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-75136 json | UpSignOn for Windows before 7.19.0 contains an insecure credential storage vulnerability that allows local attackers to retri... | Not Provided | 2026-09-02 | 2026-09-03 |
| CVE-2026-70737 json | Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: St... | Not Provided | 2026-08-18 | 2026-08-25 |
| CVE-2026-68535 json | Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5.2 did not invoke the block type controller's validate(... | Not Provided | 2026-09-11 | 2026-09-14 |
| CVE-2026-62867 json | Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.... | Not Provided | 2026-08-21 | 2026-08-21 |