Razer records
20 published records for vendor razer.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 5%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-59 Improper Link Resolution Before File Access ('Link Following')4
- CWE-732 Incorrect Permission Assignment for Critical Resource3
- CWE-269 Improper Privilege Management3
- CWE-427 Uncontrolled Search Path Element2
- CWE-276 Incorrect Default Permissions2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
20 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
65This week | CVE-2017-9769Weaponized | A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpenProcess allowing a razer · synapse | Critical9.8 | — | 85.5% | Aug 2, 2017 |
62This week | CVE-2022-29013Proof of concept | A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary commandsrazer · sila firmware · CWE-78 | Critical9.8 | — | 76.9% | Jun 8, 2022 |
34Monitor | CVE-2022-29014Proof of concept | A local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary files.razer · sila firmware | High7.5 | — | 11.8% | Jun 8, 2022 |
34Monitor | CVE-2020-16602Proof of concept | Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in whicrazer · chroma sdk · CWE-362 | High8.1 | — | 6.0% | Sep 2, 2020 |
33Monitor | CVE-2017-11652No exploit | Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the CrashReporter directory, which allows local users to gain privileges virazer · synapse · CWE-732 | High8.4 | — | 0.4% | Aug 18, 2017 |
31Monitor | CVE-2022-47631No exploit | Razer Synapse through 3.7.1209.121307 allows privilege escalation due to an unsafe installation path and improper privilege management.razer · synapse · CWE-367 | High7.8 | — | 0.4% | Sep 14, 2023 |
31Monitor | CVE-2017-11653No exploit | Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the Devices directory, which allows local users to gain privileges via a Trrazer · synapse · CWE-732 | High7.8 | — | 0.4% | Aug 18, 2017 |
31Monitor | CVE-2023-3513No exploit | RazerCentralService Unsafe Deserialization Escalation of Privilegerazer · razer central · CWE-269 | High7.8 | — | 0.3% | Jul 14, 2023 |
31Monitor | CVE-2017-14398No exploit | rzpnk.sys in Razer Synapse 2.20.15.1104 allows local users to read and write to arbitrary memory locations, and consequently gain privilegesrazer · synapse · CWE-119 | High7.8 | — | 0.3% | Sep 13, 2017 |
31Monitor | CVE-2022-45697No exploit | Arbitrary File Delete vulnerability in Razer Central before v7.8.0.381 when handling files in the Accounts directory.razer · razer central · CWE-59 | High7.8 | — | 0.3% | Feb 27, 2023 |
31Monitor | CVE-2023-3514No exploit | RazerCentralSerivce Unsafe Named Pipe Permission Escalation of Privilege Vulnerabilityrazer · razer central · CWE-269 | High7.8 | — | 0.2% | Jul 14, 2023 |
31Monitor | CVE-2025-9871No exploit | Razer Synapse 3 Chroma Connect Link Following Local Privilege Escalation Vulnerabilityrazer · synapse · CWE-59 | High7.8 | — | 0.2% | Oct 29, 2025 |
31Monitor | CVE-2025-9869No exploit | Razer Synapse 3 Macro Module Link Following Local Privilege Escalation Vulnerabilityrazer · synapse · CWE-59 | High7.8 | — | 0.2% | Oct 29, 2025 |
31Monitor | CVE-2025-9870No exploit | Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerabilityrazer · synapse · CWE-59 | High7.8 | — | 0.2% | Oct 29, 2025 |
31Monitor | CVE-2025-27811No exploit | A local privilege escalation in the razer_elevation_service.exe in Razer Synapse 4 through 4.0.86.2502180127 allows a local attacker to escarazer · synapse 4 · CWE-269 | High7.8 | — | 0.1% | Jun 4, 2025 |
29Monitor | CVE-2021-44226No exploit | Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGrazer · synapse · CWE-427 | High7.3 | — | 0.9% | Mar 23, 2022 |
27Monitor | CVE-2022-47632No exploit | Razer Synapse before 3.7.0830.081906 allows privilege escalation due to an unsafe installation path, improper privilege management, and imprrazer · synapse · CWE-427 | Medium6.8 | — | 0.6% | Jan 27, 2023 |
22Monitor | CVE-2021-30493No exploit | Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the ChromaBrrazer · synapse · CWE-276 | Medium5.5 | — | 0.5% | Apr 14, 2021 |
22Monitor | CVE-2021-30494No exploit | Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the Razer Chrazer · synapse · CWE-276 | Medium5.5 | — | 0.5% | Apr 14, 2021 |
22Monitor | CVE-2019-13142No exploit | The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user using an executablerazer · surround · CWE-732 | Medium5.5 | — | 0.3% | Jul 9, 2019 |
- CVE-2017-976965This week
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpenProcess allowing a
CriticalCVSS 9.8WeaponizedEPSS 86%razer · synapseAug 2, 2017
- CVE-2022-2901362This week
A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary commands
CriticalCVSS 9.8Proof of conceptEPSS 77%razer · sila firmwareJun 8, 2022
- CVE-2022-2901434Monitor
A local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary files.
HighCVSS 7.5Proof of conceptEPSS 12%razer · sila firmwareJun 8, 2022
- CVE-2020-1660234Monitor
Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in whic
HighCVSS 8.1Proof of conceptEPSS 6%razer · chroma sdkSep 2, 2020
- CVE-2017-1165233Monitor
Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the CrashReporter directory, which allows local users to gain privileges vi
HighCVSS 8.4No exploitEPSS 0%razer · synapseAug 18, 2017
- CVE-2022-4763131Monitor
Razer Synapse through 3.7.1209.121307 allows privilege escalation due to an unsafe installation path and improper privilege management.
HighCVSS 7.8No exploitEPSS 0%razer · synapseSep 14, 2023
- CVE-2017-1165331Monitor
Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the Devices directory, which allows local users to gain privileges via a Tr
HighCVSS 7.8No exploitEPSS 0%razer · synapseAug 18, 2017
- CVE-2023-351331Monitor
RazerCentralService Unsafe Deserialization Escalation of Privilege
HighCVSS 7.8No exploitEPSS 0%razer · razer centralJul 14, 2023
- CVE-2017-1439831Monitor
rzpnk.sys in Razer Synapse 2.20.15.1104 allows local users to read and write to arbitrary memory locations, and consequently gain privileges
HighCVSS 7.8No exploitEPSS 0%razer · synapseSep 13, 2017
- CVE-2022-4569731Monitor
Arbitrary File Delete vulnerability in Razer Central before v7.8.0.381 when handling files in the Accounts directory.
HighCVSS 7.8No exploitEPSS 0%razer · razer centralFeb 27, 2023
- CVE-2023-351431Monitor
RazerCentralSerivce Unsafe Named Pipe Permission Escalation of Privilege Vulnerability
HighCVSS 7.8No exploitEPSS 0%razer · razer centralJul 14, 2023
- CVE-2025-987131Monitor
Razer Synapse 3 Chroma Connect Link Following Local Privilege Escalation Vulnerability
HighCVSS 7.8No exploitEPSS 0%razer · synapseOct 29, 2025
- CVE-2025-986931Monitor
Razer Synapse 3 Macro Module Link Following Local Privilege Escalation Vulnerability
HighCVSS 7.8No exploitEPSS 0%razer · synapseOct 29, 2025
- CVE-2025-987031Monitor
Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerability
HighCVSS 7.8No exploitEPSS 0%razer · synapseOct 29, 2025
- CVE-2025-2781131Monitor
A local privilege escalation in the razer_elevation_service.exe in Razer Synapse 4 through 4.0.86.2502180127 allows a local attacker to esca
HighCVSS 7.8No exploitEPSS 0%razer · synapse 4Jun 4, 2025
- CVE-2021-4422629Monitor
Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROG
HighCVSS 7.3No exploitEPSS 1%razer · synapseMar 23, 2022
- CVE-2022-4763227Monitor
Razer Synapse before 3.7.0830.081906 allows privilege escalation due to an unsafe installation path, improper privilege management, and impr
MediumCVSS 6.8No exploitEPSS 1%razer · synapseJan 27, 2023
- CVE-2021-3049322Monitor
Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the ChromaBr
MediumCVSS 5.5No exploitEPSS 1%razer · synapseApr 14, 2021
- CVE-2021-3049422Monitor
Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the Razer Ch
MediumCVSS 5.5No exploitEPSS 0%razer · synapseApr 14, 2021
- CVE-2019-1314222Monitor
The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user using an executable
MediumCVSS 5.5No exploitEPSS 0%razer · surroundJul 9, 2019