Disk Pulse
Vendor:
First CVE: Jan 10, 2018 · Active for 8 years
14
Total CVEs
Bottom 1%
7.0
Avg CVEs / Year
Bottom 1%
7.0
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Disk Pulse over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 10, 2018
8 years ago
Most Recent CVE
Jan 28, 2026
177 days ago
CVE Severity & Scoring
Disk Pulse14 CVEs
43%
50%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (7.1%)
Network13 (92.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (28.6%)
Unknown0 (0.0%)
Required10 (71.4%)
Privileges Required
Low10 (71.4%)
High0 (0.0%)
None4 (28.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-13696CRITICAL A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk Pulse Enterpr | Jan 24, 2018 | 9.8 | 81 | NO | YES |
CVE-2017-15663HIGH In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to contr | Jan 10, 2018 | 7.5 | 38 | NO | YES |
CVE-2025-59894HIGH Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perf | Jan 28, 2026 | 8.0 | 25 | NO | NO |
CVE-2025-59893HIGH Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perf | Jan 28, 2026 | 8.0 | 25 | NO | NO |
CVE-2025-59892HIGH Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perf | Jan 28, 2026 | 8.0 | 25 | NO | NO |
CVE-2025-59891HIGH Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perf | Jan 28, 2026 | 8.0 | 25 | NO | NO |
CVE-2020-36927HIGH DiskPulse Enterprise 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. | Jan 16, 2026 | 7.8 | 25 | NO | NO |
CVE-2025-59895HIGH Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a remote denial-of-service (DoS) vulnerability in the configuration restore functionality. The iss | Jan 28, 2026 | 7.5 | 24 | NO | NO |
CVE-2025-59900MEDIUM Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malici | Jan 28, 2026 | 5.4 | 19 | NO | NO |
CVE-2025-59899MEDIUM Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malici | Jan 28, 2026 | 5.4 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.1% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.1% of CVEs· 93rd percentile
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Disk Pulse
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.9.16 | 1 | 9.8 | 79.3% | 0 | 1 |
| 13.6.14 | 1 | 7.8 | 0.2% | 0 | 0 |
| 10.4.18 | 10 | 6.7 | 0.2% | 0 | 0 |
| 10.1.18 | 1 | 7.5 | 13.2% | 0 | 1 |