Flexense develops a portfolio of Windows-based disk and file management utilities—including SyncBreeze, DiskPulse, DiskBoss, VX Search, and DiskSavvy—that target both individual users and small-to-medium enterprises for storage optimization and synchronization tasks. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the local-system and web-interface attack surfaces present in desktop and administrative tools. The exposure recurs across these products through weakness classes centered on input handling and boundary validation: cross-site scripting, memory buffer overflows, unquoted search paths, cross-site request forgery, and improper security checks, which are characteristic of applications that combine filesystem access with local or network interfaces. The presence of these flaws across a tool portfolio widely installed in managed environments makes them relevant to defenders conducting inventory and remediation planning. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flexense over time
Signals from CVEs in this vendor scope (53 CVEs).
53 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-8065HIGH An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access violation on the syncbrs.exe memory region that can be trigge | Mar 12, 2018 | 7.5 | 82 | NO | YES |
CVE-2017-13696CRITICAL A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk Pulse Enterpr | Jan 24, 2018 | 9.8 | 81 | NO | YES |
CVE-2017-7310HIGH A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9, DiskPulse before 10.6, DiskSavvy before 10.6, DupScout bef | Mar 29, 2017 | 7.8 | 74 | NO | YES |
CVE-2018-5262CRITICAL A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute arbitrary code in the context of a highly privileged accoun | Jan 12, 2018 | 9.8 | 64 | NO | YES |
CVE-2018-6481CRITICAL A buffer overflow vulnerability in the control protocol of Disk Savvy Enterprise v10.4.18 allows remote attackers to execute arbitrary code by sending a crafted packet to TCP port | Feb 27, 2018 | 9.8 | 53 | NO | YES |
CVE-2017-14980CRITICAL Buffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /login. | Oct 10, 2017 | 9.8 | 53 | NO | YES |
CVE-2017-6416CRITICAL An issue was discovered in SysGauge 1.5.18. A buffer overflow vulnerability in SMTP connection verification leads to arbitrary code execution. The attack vector is a crafted SMTP d | Mar 6, 2017 | 9.8 | 48 | NO | YES |
CVE-2017-15220CRITICAL Flexense VX Search Enterprise 10.1.12 is vulnerable to a buffer overflow via an empty POST request to a long URI beginning with a /../ substring. This allows remote attackers to ex | Oct 11, 2017 | 9.8 | 46 | NO | YES |
CVE-2018-5359HIGH The server in Flexense SysGauge 3.6.18 operating on port 9221 can be exploited remotely with the attacker gaining system-level access because of a Buffer Overflow. | Jan 23, 2018 | 8.1 | 40 | NO | YES |
CVE-2017-15663HIGH In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to contr | Jan 10, 2018 | 7.5 | 38 | NO | YES |
Signals from CVEs in this vendor scope (53 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flexense.
Media articles that mention a CVE ID that affects a product developed by Flexense — matched by CVE ID, not by vendor name.