Primx maintains a small portfolio of enterprise and communication products including ZoneCentral, Zed, and ZedMail, occupying a focused but strategically visible niche in the vulnerability landscape. The vendor's disclosures recur around data-protection and access-control weaknesses—notably cleartext storage of sensitive information, exposure of confidential data to unauthorized actors, improper access controls, and path-traversal conditions—reflecting the authentication and information-handling demands of gateway and messaging platforms. A meaningful share of these vulnerabilities reach serious severity; defenders should prioritize Primx advisories particularly where systems handle sensitive communications or administrative access. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Primx over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16518CRITICAL A directory traversal vulnerability with remote code execution in Prim'X Zed! FREE through 1.0 build 186 and Zed! Limited Edition through 6.1 build 2208 allows creation of arbitrar | Sep 5, 2018 | 9.8 | 30 | NO | NO |
CVE-2024-46465HIGH By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Config | Nov 15, 2024 | 7.8 | 21 | NO | NO |
CVE-2023-50444HIGH By default, .ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualification submission); | Dec 13, 2023 | 7.5 | 21 | NO | NO |
CVE-2019-7312MEDIUM Limited plaintext disclosure exists in PRIMX Zed Entreprise for Windows before 6.1.2240, Zed Entreprise for Windows (ANSSI qualification submission) before 6.1.2150, Zed Entreprise | Feb 3, 2019 | 5.3 | 19 | NO | NO |
CVE-2023-50440MEDIUM ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL f | Dec 13, 2023 | 5.5 | 18 | NO | NO |
CVE-2023-50442MEDIUM Encrypted folders created by PRIMX ZONECENTRAL through 2023.5 can be modified by a local attacker (with appropriate privileges) so that specific file types are excluded from encryp | Dec 13, 2023 | 5.5 | 17 | NO | NO |
CVE-2023-50439MEDIUM ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission), ZED! for Windows before Q.2021.2 (ANSSI qualification submission), ZONECENTRAL f | Dec 13, 2023 | 5.3 | 17 | NO | NO |
CVE-2023-50441MEDIUM Encrypted folders created by PRIMX ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission) or ZONECENTRAL for Windows before 2023.5 can be modified by an unauthent | Dec 13, 2023 | 5.5 | 17 | NO | NO |
CVE-2018-19279MEDIUM PRIMX ZoneCentral before 6.1.2236 on Windows sometimes leaks the plaintext of NTFS files. On non-SSD devices, this is limited to a 5-second window and file sizes less than 600 byte | Nov 14, 2018 | 4.3 | 17 | NO | NO |
CVE-2023-50443MEDIUM Encrypted disks created by PRIMX CRYHOD for Windows before Q.2020.4 (ANSSI qualification submission) or CRYHOD for Windows before 2023.5 can be modified by an unauthenticated attac | Dec 13, 2023 | 4.6 | 16 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Primx.
Media articles that mention a CVE ID that affects a product developed by Primx — matched by CVE ID, not by vendor name.