Sysax records
12 published records for vendor sysax.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 3 · 25%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-121 Stack-based Buffer Overflow1
- CWE-248 Uncaught Exception1
- CWE-384 Session Fixation1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2012-6530Weaponized | Stack-based buffer overflow in Sysax Multi Server before 5.52, when HTTP is enabled, allows remote authenticated users with the create foldesysax · multi server · CWE-119 | High7.1 | — | 46.1% | Jan 31, 2013 |
38Monitor | CVE-2012-10060Weaponized | Sysax Multi Server < 5.55 SSH Username Buffer Overflowsysax · multi server · CWE-121 | Critical9.3 | — | 3.0% | Aug 13, 2025 |
37Monitor | CVE-2009-4790Proof of concept | Multiple directory traversal vulnerabilities in Sysax Multi Server 4.5 allow remote authenticated users to read or modify arbitrary files visysax · multi server · CWE-22 | Critical9.0 | — | 3.9% | Apr 22, 2010 |
35Monitor | CVE-2020-13229No exploit | An issue was discovered in Sysax Multi Server 6.90.sysax · multi server · CWE-384 | High8.8 | — | 1.6% | Jun 2, 2020 |
34Monitor | CVE-2013-10065Weaponized | Sysax Multi-Server <= 6.10 SSHD Key Exchange DoSsysax · multi server · CWE-248 | High8.7 | — | 1.6% | Aug 5, 2025 |
30Monitor | CVE-2024-53458No exploit | Sysax Multi Server 6.99 is vulnerable to a denial of service (DoS) condition when processing specially crafted SSH packets.sysax · multi server · CWE-400 | High7.5 | — | 0.5% | Mar 5, 2025 |
26Monitor | CVE-2020-23574No exploit | When uploading a file in Sysax Multi Server 6.90, an authenticated user can modify the filename="" parameter in the uploadfile_name1.htm forsysax · multi server · CWE-119 | Medium6.5 | — | 1.0% | Aug 19, 2020 |
25Monitor | CVE-2020-13228Proof of concept | An issue was discovered in Sysax Multi Server 6.90.sysax · multi server · CWE-79 | Medium6.1 | — | 3.1% | Jun 2, 2020 |
22Monitor | CVE-2020-13227No exploit | An issue was discovered in Sysax Multi Server 6.90.sysax · multi server · CWE-22 | Medium5.3 | — | 1.9% | Jun 2, 2020 |
21Monitor | CVE-2024-53459No exploit | Sysax Multi Server 6.99 is vulnerable to Cross Site Scripting (XSS) via the /scgi?sid parameter.sysax · multi server · CWE-79 | Medium5.4 | — | 0.3% | Dec 2, 2024 |
20Monitor | CVE-2023-54337No exploit | Sysax Multi Server 6.95 - 'Password' Denial of Service (PoC)sysax · multi server · CWE-1284 | Medium5.1 | — | 0.5% | Jan 13, 2026 |
17Monitor | CVE-2009-4800Proof of concept | Directory traversal vulnerability in Sysax Multi Server 4.3 and 4.5 allows remote authenticated users to delete arbitrary files via a ..// (sysax · multi server · CWE-22 | Medium4.0 | — | 1.9% | Apr 22, 2010 |
- CVE-2012-653042Plan
Stack-based buffer overflow in Sysax Multi Server before 5.52, when HTTP is enabled, allows remote authenticated users with the create folde
HighCVSS 7.1WeaponizedEPSS 46%sysax · multi serverJan 31, 2013
- CVE-2012-1006038Monitor
Sysax Multi Server < 5.55 SSH Username Buffer Overflow
CriticalCVSS 9.3WeaponizedEPSS 3%sysax · multi serverAug 13, 2025
- CVE-2009-479037Monitor
Multiple directory traversal vulnerabilities in Sysax Multi Server 4.5 allow remote authenticated users to read or modify arbitrary files vi
CriticalCVSS 9.0Proof of conceptEPSS 4%sysax · multi serverApr 22, 2010
- CVE-2020-1322935Monitor
An issue was discovered in Sysax Multi Server 6.90.
HighCVSS 8.8No exploitEPSS 2%sysax · multi serverJun 2, 2020
- CVE-2013-1006534Monitor
Sysax Multi-Server <= 6.10 SSHD Key Exchange DoS
HighCVSS 8.7WeaponizedEPSS 2%sysax · multi serverAug 5, 2025
- CVE-2024-5345830Monitor
Sysax Multi Server 6.99 is vulnerable to a denial of service (DoS) condition when processing specially crafted SSH packets.
HighCVSS 7.5No exploitEPSS 1%sysax · multi serverMar 5, 2025
- CVE-2020-2357426Monitor
When uploading a file in Sysax Multi Server 6.90, an authenticated user can modify the filename="" parameter in the uploadfile_name1.htm for
MediumCVSS 6.5No exploitEPSS 1%sysax · multi serverAug 19, 2020
- CVE-2020-1322825Monitor
An issue was discovered in Sysax Multi Server 6.90.
MediumCVSS 6.1Proof of conceptEPSS 3%sysax · multi serverJun 2, 2020
- CVE-2020-1322722Monitor
An issue was discovered in Sysax Multi Server 6.90.
MediumCVSS 5.3No exploitEPSS 2%sysax · multi serverJun 2, 2020
- CVE-2024-5345921Monitor
Sysax Multi Server 6.99 is vulnerable to Cross Site Scripting (XSS) via the /scgi?sid parameter.
MediumCVSS 5.4No exploitEPSS 0%sysax · multi serverDec 2, 2024
- CVE-2023-5433720Monitor
Sysax Multi Server 6.95 - 'Password' Denial of Service (PoC)
MediumCVSS 5.1No exploitEPSS 1%sysax · multi serverJan 13, 2026
- CVE-2009-480017Monitor
Directory traversal vulnerability in Sysax Multi Server 4.3 and 4.5 allows remote authenticated users to delete arbitrary files via a ..// (
MediumCVSS 4.0Proof of conceptEPSS 2%sysax · multi serverApr 22, 2010