Tag
critical
advisory
Insufficient Entropy Vulnerability in Synology DiskStation Manager Login Logic
1 TTP 6 CVEsSynology DiskStation Manager (DSM) contains an insufficient entropy vulnerability in its login logic that allows remote, unauthenticated attackers to perform arbitrary file read/write operations and trigger a denial-of-service condition.
DiskStation Manager +6
vulnerability
critical
remote-code-execution
file-read-write
dsm
file-access
synology
cve
+4
1t
6c
high
advisory
Unauthenticated SQL Execution Vulnerability in Recce OSS Server (CVE-2026-49360)
1 rule 3 TTPsRecce OSS server deployments are vulnerable to unauthenticated SQL execution via the query run API when configured with a DuckDB-backed project, allowing attackers to use DuckDB filesystem primitives to read and write arbitrary files accessible to the server process, potentially leading to data disclosure, tampering, or stored XSS.
recce
web-vulnerability
sql-injection
file-read-write
rce
data-exfiltration
1r
3t