Multi Server

Vendor:

First CVE: Apr 22, 2010 · Active for 16 years

12
Total CVEs
More Total CVEs than 90% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Multi Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 22, 2010
16 years ago
Most Recent CVE
Jan 13, 2026
192 days ago

CVE Severity & Scoring

Multi Server12 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (75.0%)
Unknown3 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (75.0%)
High0 (0.0%)
Unknown3 (25.0%)
User Interaction
None6 (50.0%)
Unknown3 (25.0%)
Required3 (25.0%)
Privileges Required
Low2 (16.7%)
High0 (0.0%)
None7 (58.3%)
Unknown3 (25.0%)

Top CVEs

Signals from CVEs in this product scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Stack-based buffer overflow in Sysax Multi Server before 5.52, when HTTP is enabled, allows remote authenticated users with the create folder permission to execute arbitrary code v
Jan 31, 20137.166NOYES
Sysax Multi Server versions prior to 5.55 contain a stack-based buffer overflow in its SSH service. When a remote attacker supplies an overly long username during authentication, t
Aug 13, 20259.842NOYES
A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A specially crafted SSH key exchange packet can trigger a crash in the service, resu
Aug 5, 20257.540NOYES
Multiple directory traversal vulnerabilities in Sysax Multi Server 4.5 allow remote authenticated users to read or modify arbitrary files via crafted FTP commands. NOTE: the prove
Apr 22, 20109.039NOYES
Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the application. Attackers can overwrite the
Jan 13, 20269.128NONO
An issue was discovered in Sysax Multi Server 6.90. A session can be hijacked if one observes the sid value in any /scgi URI, because it is an authentication token.
Jun 2, 20208.827NONO
An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter.
Jun 2, 20206.125NOYES
When uploading a file in Sysax Multi Server 6.90, an authenticated user can modify the filename="" parameter in the uploadfile_name1.htm form to a length of 368 or more bytes. This
Aug 19, 20206.523NONO
Directory traversal vulnerability in Sysax Multi Server 4.3 and 4.5 allows remote authenticated users to delete arbitrary files via a ..// (dot dot slash slash) in a DELE command.
Apr 22, 20104.022NOYES
Sysax Multi Server 6.99 is vulnerable to a denial of service (DoS) condition when processing specially crafted SSH packets.
Mar 5, 20257.521NONO

Exploit Exposure

Signals from CVEs in this product scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
25.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
33.3% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (12 CVEs).

Media Mentions

Signals from CVEs in this product scope (12 CVEs).

Top CNAs Publishing CVEs For Multi Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.9926.50.4%00
6.9519.10.5%00
6.9046.71.9%01
6.1017.51.1%01
4.536.717.3%03
4.325.524.0%02