📦

download_station

Vendor: synology

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 2 Remote Access
Total CVEs 48 Total Indexed
Avg. EPSS 1.26% Exploit Prob.
Latest CVE CVE-2025-58465 Nov 07

Security Vulnerability Index

Page 2 / 5
4.3 CVSS

Cross-site scripting (XSS) vulnerability in the "Create download task via file upload" feature in Synology Download Station before 3.5-2962 allows remote attackers to inject arbitrary web script or HTML via the name element in the Info dictionary in a torrent file.

EPSS: 2.09%