Skip to main content

Vendor archive

flexense CVEs

Beta · best-effort

53 CVEs tagged to vendor flexense8 Critical, 33 High, 12 Medium, 0 Low, 0 Unrated.

CVE-2020-37100

Published Feb 3, 2026

Sync Breeze Enterprise 12.4.18 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59900

Published Jan 28, 2026

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malic…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59899

Published Jan 28, 2026

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malic…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59898

Published Jan 28, 2026

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malic…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59897

Published Jan 28, 2026

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malic…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59896

Published Jan 28, 2026

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malic…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59895

Published Jan 28, 2026

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a remote denial-of-service (DoS) vulnerability in the configuration restore functionality. The is…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59894

Published Jan 28, 2026

Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to per…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59893

Published Jan 28, 2026

Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to per…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59892

Published Jan 28, 2026

Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to per…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59891

Published Jan 28, 2026

Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to per…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36946

Published Jan 27, 2026

SyncBreeze 10.0.28 contains a denial of service vulnerability in the login endpoint that allows remote attackers to crash the service. Attackers can send an oversized payload in t…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2021-47809

Published Jan 16, 2026

Disk Sorter Enterprise 13.6.12 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary co…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-47807

Published Jan 16, 2026

Sync Breeze 13.6.18 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attacke…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-47806

Published Jan 16, 2026

Dup Scout 13.5.28 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-47805

Published Jan 16, 2026

Disk Savvy 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attacker…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36930

Published Jan 16, 2026

SysGauge Server 7.9.18 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to potentially execute arbitrary code. Attacker…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36927

Published Jan 16, 2026

DiskPulse Enterprise 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36882

Published Dec 5, 2025

Flexsense DiskBoss 7.7.14 allows unauthenticated attackers to upload arbitrary files via /Command/Search Files/Directory field, leading to a denial of service by crashing the appl…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36881

Published Dec 5, 2025

Flexsense DiskBoss 7.7.14 contains a local buffer overflow vulnerability in the 'Input Directory' component that allows unauthenticated attackers to execute arbitrary code on the…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36880

Published Dec 5, 2025

Flexsense DiskBoss 7.7.14 contains a local buffer overflow vulnerability in the 'Reports and Data Directory' field that allows an attacker to execute arbitrary code on the system.

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49575

Published May 24, 2024

A vulnerability has been discovered in VX Search Enterprise affecting version 10.2.14, in Sync Breeze Enterprise Server 10.4.18 version, and in Disk Pulse Enterprise 10.4.18 versi…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49574

Published May 24, 2024

A vulnerability has been discovered in VX Search Enterprise affecting version 10.2.14 that could allow an attacker to execute persistent XSS through /add_job in job_name. This vul…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49573

Published May 24, 2024

A vulnerability has been discovered in VX Search Enterprise affecting version 10.2.14 that could allow an attacker to execute persistent XSS through /add_command_action in action_…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49572

Published May 24, 2024

A vulnerability has been discovered in VX Search Enterprise affecting version 10.2.14, and in Disk Pulse Enterprise 10.4.18 version, that could allow an attacker to execute persis…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 53 CVEsPage 1 of 3