A vulnerability, which was classified as problematic, has been found in portabilis i-educar up to 2.8. Impacted is an unknown function of the file ieducar/intranet/include/clsCampos.inc.php. Performing a manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2024-45057. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
The vendor confirms: "The reported attack vector was tested against the corrected code, and the previously described Cross-Site Scripting behavior could no longer be reproduced."
A vulnerability was found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. It has been declared as critical. Impacted is an unknown function of the component Desktop API. Executing a manipulation can lead to path traversal.
The identification of this vulnerability is CVE-2026-40535. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability labeled as problematic has been found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. This impacts an unknown function of the component Desktop API. Such manipulation leads to information disclosure.
This vulnerability is listed as CVE-2026-40533. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
A vulnerability classified as problematic was found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. This affects an unknown part of the component PersonMail API. The manipulation results in server-side request forgery.
This vulnerability is reported as CVE-2026-40537. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability was found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 and classified as problematic. This vulnerability affects unknown code of the component Wallpaper Path. Such manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2026-40532. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability was found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. It has been rated as problematic. The affected element is an unknown function of the component Audio API. The manipulation leads to path traversal.
This vulnerability is referenced as CVE-2026-40536. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
A vulnerability classified as problematic has been found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. Affected by this issue is some unknown functionality of the component Video API. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2026-40534. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.