Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sysax

First CVE: Apr 22, 2010Active for: 16 yearsTotal CVEs: 12
59.2
VTI Score
TOP TARGET

Sysax develops a focused multi-server product line that handles file transfer, remote access, and data management functions across enterprise deployments, presenting a modestly represented but notably prominent vulnerability footprint. Its vulnerabilities skew toward serious outcomes with an elevated share reaching critical severity and a strong tendency toward public exploit availability, while recurrent weakness classes including path traversal, cross-site scripting, buffer boundary violations, and input validation flaws reflect the complexity of parsing and access control in file-transfer and session-management code. Current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sysax over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 22, 2010
16 years ago
Most Recent CVE
Jan 13, 2026
192 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-6530HIGH
Stack-based buffer overflow in Sysax Multi Server before 5.52, when HTTP is enabled, allows remote authenticated users with the create folder permission to execute arbitrary code v
Jan 31, 20137.166NOYES
CVE-2012-10060CRITICAL
Sysax Multi Server versions prior to 5.55 contain a stack-based buffer overflow in its SSH service. When a remote attacker supplies an overly long username during authentication, t
Aug 13, 20259.842NOYES
CVE-2013-10065HIGH
A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A specially crafted SSH key exchange packet can trigger a crash in the service, resu
Aug 5, 20257.540NOYES
CVE-2009-4790HIGH
Multiple directory traversal vulnerabilities in Sysax Multi Server 4.5 allow remote authenticated users to read or modify arbitrary files via crafted FTP commands. NOTE: the prove
Apr 22, 20109.039NOYES
CVE-2023-54337CRITICAL
Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the application. Attackers can overwrite the
Jan 13, 20269.128NONO
CVE-2020-13229HIGH
An issue was discovered in Sysax Multi Server 6.90. A session can be hijacked if one observes the sid value in any /scgi URI, because it is an authentication token.
Jun 2, 20208.827NONO
CVE-2020-13228MEDIUM
An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter.
Jun 2, 20206.125NOYES
CVE-2020-23574MEDIUM
When uploading a file in Sysax Multi Server 6.90, an authenticated user can modify the filename="" parameter in the uploadfile_name1.htm form to a length of 368 or more bytes. This
Aug 19, 20206.523NONO
CVE-2009-4800MEDIUM
Directory traversal vulnerability in Sysax Multi Server 4.3 and 4.5 allows remote authenticated users to delete arbitrary files via a ..// (dot dot slash slash) in a DELE command.
Apr 22, 20104.022NOYES
CVE-2024-53458HIGH
Sysax Multi Server 6.99 is vulnerable to a denial of service (DoS) condition when processing specially crafted SSH packets.
Mar 5, 20257.521NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
42%
42%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (75.0%)
Unknown3 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (75.0%)
High0 (0.0%)
Unknown3 (25.0%)
User Interaction
None6 (50.0%)
Unknown3 (25.0%)
Required3 (25.0%)
Privileges Required
Low2 (16.7%)
High0 (0.0%)
None7 (58.3%)
Unknown3 (25.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
25.0% of CVEs· 99th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
33.3% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sysax.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sysax — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sysax's Products

View all 2 CNAs →

Top CWEs