Skip to main content

Vendor/product archive

synology / calendar CVEs

Beta · best-effort

11 CVEs tagged to synology / calendar0 Critical, 1 High, 10 Medium, 0 Low, 0 Unrated.

CVE-2022-22686

Published Jul 26, 2022

Cross-Site Request Forgery (CSRF) vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to hijack the authentication of admini…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22682

Published Jul 12, 2022

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Event Management in Synology Calendar before 2.4.5-10930 allows remote authen…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-34812

Published Jun 18, 2021

Use of hard-coded credentials vulnerability in php component in Synology Calendar before 2.4.0-0761 allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11829

Published Jun 30, 2019

OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar before 2.3.1-0617 allows remote attackers to execute arbitrary commands via the crafted 'X-…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11825

Published Jun 30, 2019

Cross-site scripting (XSS) vulnerability in Event Editor in Synology Calendar before 2.3.0-0615 allows remote attackers to inject arbitrary web script or HTML via the title parame…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11820

Published May 9, 2019

Information exposure through process environment vulnerability in Synology Calendar before 2.3.3-0620 allows local users to obtain credentials via cmdline.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-13299

Published Apr 1, 2019

Relative path traversal vulnerability in Attachment Uploader in Synology Calendar before 2.2.2-0532 allows remote authenticated users to upload arbitrary files via the filename pa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-8927

Published Jun 14, 2018

Improper authorization vulnerability in SYNO.Cal.Event in Calendar before 2.1.2-0511 allows remote authenticated users to create arbitrary events via the (1) cal_id or (2) origina…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-8915

Published May 10, 2018

Cross-site scripting (XSS) vulnerability in Notification Center in Synology Calendar before 2.1.1-0502 allows remote authenticated users to inject arbitrary web script or HTML via…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15891

Published Dec 8, 2017

Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authenticated users to modify calendar event via unspecified vecto…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1