Skip to main content

Vendor/product archive

flexense / syncbreeze CVEs

Beta · best-effort

23 CVEs tagged to flexense / syncbreeze3 Critical, 14 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2020-37100

Published Feb 3, 2026

Sync Breeze Enterprise 12.4.18 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59900

Published Jan 28, 2026

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malic…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59899

Published Jan 28, 2026

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malic…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59898

Published Jan 28, 2026

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malic…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59897

Published Jan 28, 2026

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malic…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59896

Published Jan 28, 2026

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malic…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59895

Published Jan 28, 2026

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a remote denial-of-service (DoS) vulnerability in the configuration restore functionality. The is…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59894

Published Jan 28, 2026

Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to per…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59893

Published Jan 28, 2026

Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to per…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59892

Published Jan 28, 2026

Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to per…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59891

Published Jan 28, 2026

Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to per…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36946

Published Jan 27, 2026

SyncBreeze 10.0.28 contains a denial of service vulnerability in the login endpoint that allows remote attackers to crash the service. Attackers can send an oversized payload in t…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10563

Published May 2, 2018

An XSS in Flexense SyncBreeze affects all versions (tested from SyncBreeze Enterprise from v10.1 to v10.7).

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-8065

Published Mar 12, 2018

An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access violation on the syncbrs.exe memory region that can be trigg…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17996

Published Feb 6, 2018

A buffer overflow vulnerability in "Add command" functionality exists in Flexense SyncBreeze Enterprise <= 10.3.14. The vulnerability can be triggered by an authenticated attacker…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6537

Published Feb 2, 2018

A buffer overflow vulnerability in the control protocol of Flexense SyncBreeze Enterprise v10.4.18 allows remote attackers to execute arbitrary code by sending a crafted packet to…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-15664

Published Jan 10, 2018

In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to con…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17088

Published Dec 19, 2017

The Enterprise version of SyncBreeze 10.2.12 and earlier is affected by a Remote Denial of Service vulnerability. The web server does not check bounds when reading server requests…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17099

Published Dec 3, 2017

There exists an unauthenticated SEH based Buffer Overflow vulnerability in the HTTP server of Flexense SyncBreeze Enterprise v10.1.16. When sending a GET request with an excessive…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15950

Published Oct 31, 2017

Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary code execution. The flaw is triggered by providing a long inp…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14980

Published Oct 10, 2017

Buffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /login.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-23 of 23 CVEsPage 1 of 1