Storage Manager
38 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Storage Manager, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Storage Manager CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 5 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 3 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 1 |
| 2026-05 | 1 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 38 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical13
- High10
- Medium13
- Low2
Latest CVEs
The 15 most recently published vulnerabilities affecting Storage Manager.
- CVE-2026-2237A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive i...6.2
- CVE-2026-23772Dell Storage Manager - Replay Manager for Microsoft Servers, version(s) 8.0, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially...7.3
- CVE-2025-43994Dell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could pot...8.6
- CVE-2025-43995Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vu...9.8
- CVE-2025-46425Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could...6.5
- CVE-2025-22476Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged att...5.5
- CVE-2025-22477Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent network access could potentially explo...8.3
- CVE-2025-22478Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An unauthenticated attacker with adjacent network ...8.1
- CVE-2025-22479Dell Storage Center - Dell Storage Manager, version(s) 20.0.21, contain(s) an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attack...3.5
- CVE-2025-23379Dell Storage Center - Dell Storage Manager, version(s) 21.0.20, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An unauthenticated ...3.5
- CVE-2021-32528QSAN Storage Manager - Exposure of Sensitive Information to an Unauthorized Actor5.3
- CVE-2021-32527QSAN Storage Manager - Path Traversal-27.5
- CVE-2021-32526QSAN Storage Manager - Incorrect Permission Assignment for Critical Resource6.5
- CVE-2021-32525QSAN Storage Manager - Use of Hard-coded Password-29.1
- CVE-2021-32524QSAN Storage Manager - Command Injection-39.1
Product grouping is registry-driven, with AI assist and human review. How it works