CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

synology

active_backup_for_business_agent

7 known vulnerabilities · sorted by CVSS score

CVE-2024-47265
MEDIUM6.5

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users to write specific files via unspecified vectors.

synology / active_backup_for_business_agent+2
Network
Published Feb 13, 2025
CVE-2023-52949
MEDIUM5.5

Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecified vectors.

synology / active_backup_for_business_agent
Local
Published Sep 26, 2024
CVE-2023-52950
MEDIUM5.3

Missing encryption of sensitive data vulnerability in login component in Synology Active Backup for Business Agent before 2.7.0-3221 allows adjacent man-in-the-middle attackers to obtain user credential via unspecified vectors.

synology / active_backup_for_business_agent
Adjacent
Published Sep 26, 2024
CVE-2023-52948
MEDIUM5.0

Missing encryption of sensitive data vulnerability in settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecified vectors.

synology / active_backup_for_business_agent
Local
Published Sep 26, 2024
CVE-2024-47264
MEDIUM4.9

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users with administrator privileges to delete arbitrary files via unspecified vectors.

synology / active_backup_for_business_agent+2
Network
Published Feb 13, 2025
CVE-2023-52947
MEDIUM4.0

Missing authentication for critical function vulnerability in logout functionality in Synology Active Backup for Business Agent before 2.6.3-3101 allows local users to logout the client via unspecified vectors. The backup functionality will continue to operate and will not be affected by the logout.

synology / active_backup_for_business_agent
Local
Published Sep 26, 2024
CVE-2024-47266
LOW2.7

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in share file list functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users with administrator privileges to read specific files containing non-sensitive information via unspecified vectors.

synology / active_backup_for_business_agent+2
Network
Published Feb 13, 2025