Skip to main content

Vendor archive

synametrics CVEs

Beta · best-effort

8 CVEs tagged to vendor synametrics0 Critical, 5 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2022-26251

Published Apr 6, 2022

The HTTP interface of Synaman v5.1 and below was discovered to allow authenticated attackers to execute arbitrary code and escalate privileges.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-26250

Published Apr 6, 2022

Synaman v5.1 and below was discovered to contain weak file permissions which allows authenticated attackers to escalate privileges.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-22828

Published Jan 27, 2022

An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker to access unshared files via a modified base64-encoded fil…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10763

Published Sep 14, 2018

Multiple cross-site scripting (XSS) vulnerabilities in Synametrics SynaMan 4.0 build 1488 via the (1) Main heading or (2) Sub heading fields in the Partial Branding configuration…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3141

Published May 20, 2015

Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies Xeams 4.5 Build 5755 and earlier allow remote attackers to hijack the authentication of admi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2569

Published Jun 19, 2014

Cross-site scripting (XSS) vulnerability in Synametrics Technologies Xeams 4.4 Build 5720 allows remote attackers to inject arbitrary web script or HTML via the body of an email.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1