syncfusion kayıtları
syncfusion üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2023-26563İstismar yok | The Syncfusion EJ2 Node File Provider 0102271 is vulnerable to filesystem-server.js directory traversal.syncfusion · nodejs file system provider · CWE-22 | Kritik9,8 | — | %1,9 | 12 Tem 2023 |
40Planlayın | CVE-2023-26564İstismar yok | The Syncfusion EJ2 ASPCore File Provider 3ac357f is vulnerable to Models/PhysicalFileProvider.cs directory traversal.syncfusion · ej2 aspcore file provider · CWE-22 | Kritik9,8 | — | %1,7 | 12 Tem 2023 |
37İzleyin | CVE-2026-65687İstismar yok | Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via SVG Processingsyncfusion · standalone report designer · CWE-22 | Kritik9,3 | — | %0,9 | 23 Tem 2026 |
37İzleyin | CVE-2026-65688İstismar yok | Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Font Processingsyncfusion · standalone report designer · CWE-22 | Kritik9,3 | — | %0,9 | 23 Tem 2026 |
37İzleyin | CVE-2026-65689İstismar yok | Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Database Downloadsyncfusion · standalone report designer · CWE-22 | Kritik9,3 | — | %0,9 | 23 Tem 2026 |
34İzleyin | CVE-2026-65690İstismar yok | Bold Reports Standalone Report Designer < 14.1.12 Path Traversal RCE via File Uploadsyncfusion · standalone report designer · CWE-22 | Yüksek8,7 | — | %0,9 | 23 Tem 2026 |
21İzleyin | CVE-2025-63260İstismar yok | SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and Chat-UI Chat message.syncfusion · syncfusion · CWE-79 | Orta5,4 | — | %0,2 | 20 Mar 2026 |
- CVE-2023-2656340Planlayın
The Syncfusion EJ2 Node File Provider 0102271 is vulnerable to filesystem-server.js directory traversal.
KritikCVSS 9,8İstismar yokEPSS %2syncfusion · nodejs file system provider12 Tem 2023
- CVE-2023-2656440Planlayın
The Syncfusion EJ2 ASPCore File Provider 3ac357f is vulnerable to Models/PhysicalFileProvider.cs directory traversal.
KritikCVSS 9,8İstismar yokEPSS %2syncfusion · ej2 aspcore file provider12 Tem 2023
- CVE-2026-6568737İzleyin
Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via SVG Processing
KritikCVSS 9,3İstismar yokEPSS %1syncfusion · standalone report designer23 Tem 2026
- CVE-2026-6568837İzleyin
Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Font Processing
KritikCVSS 9,3İstismar yokEPSS %1syncfusion · standalone report designer23 Tem 2026
- CVE-2026-6568937İzleyin
Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Database Download
KritikCVSS 9,3İstismar yokEPSS %1syncfusion · standalone report designer23 Tem 2026
- CVE-2026-6569034İzleyin
Bold Reports Standalone Report Designer < 14.1.12 Path Traversal RCE via File Upload
YüksekCVSS 8,7İstismar yokEPSS %1syncfusion · standalone report designer23 Tem 2026
- CVE-2025-6326021İzleyin
SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and Chat-UI Chat message.
OrtaCVSS 5,4İstismar yokEPSS %0syncfusion · syncfusion20 Mar 2026