Multi Server
Vendor:
First CVE: Apr 22, 2010 · Active for 16 years
12
Total CVEs
More Total CVEs than 90% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Multi Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 22, 2010
16 years ago
Most Recent CVE
Jan 13, 2026
192 days ago
CVE Severity & Scoring
Multi Server12 CVEs
42%
42%
17%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (75.0%)
Unknown3 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (75.0%)
High0 (0.0%)
Unknown3 (25.0%)
User Interaction
None6 (50.0%)
Unknown3 (25.0%)
Required3 (25.0%)
Privileges Required
Low2 (16.7%)
High0 (0.0%)
None7 (58.3%)
Unknown3 (25.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-6530HIGH Stack-based buffer overflow in Sysax Multi Server before 5.52, when HTTP is enabled, allows remote authenticated users with the create folder permission to execute arbitrary code v | Jan 31, 2013 | 7.1 | 66 | NO | YES |
CVE-2012-10060CRITICAL Sysax Multi Server versions prior to 5.55 contain a stack-based buffer overflow in its SSH service. When a remote attacker supplies an overly long username during authentication, t | Aug 13, 2025 | 9.8 | 42 | NO | YES |
CVE-2013-10065HIGH A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A specially crafted SSH key exchange packet can trigger a crash in the service, resu | Aug 5, 2025 | 7.5 | 40 | NO | YES |
CVE-2009-4790HIGH Multiple directory traversal vulnerabilities in Sysax Multi Server 4.5 allow remote authenticated users to read or modify arbitrary files via crafted FTP commands. NOTE: the prove | Apr 22, 2010 | 9.0 | 39 | NO | YES |
CVE-2023-54337CRITICAL Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the application. Attackers can overwrite the | Jan 13, 2026 | 9.1 | 28 | NO | NO |
CVE-2020-13229HIGH An issue was discovered in Sysax Multi Server 6.90. A session can be hijacked if one observes the sid value in any /scgi URI, because it is an authentication token. | Jun 2, 2020 | 8.8 | 27 | NO | NO |
CVE-2020-13228MEDIUM An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter. | Jun 2, 2020 | 6.1 | 25 | NO | YES |
CVE-2020-23574MEDIUM When uploading a file in Sysax Multi Server 6.90, an authenticated user can modify the filename="" parameter in the uploadfile_name1.htm form to a length of 368 or more bytes. This | Aug 19, 2020 | 6.5 | 23 | NO | NO |
CVE-2009-4800MEDIUM Directory traversal vulnerability in Sysax Multi Server 4.3 and 4.5 allows remote authenticated users to delete arbitrary files via a ..// (dot dot slash slash) in a DELE command. | Apr 22, 2010 | 4.0 | 22 | NO | YES |
CVE-2024-53458HIGH Sysax Multi Server 6.99 is vulnerable to a denial of service (DoS) condition when processing specially crafted SSH packets. | Mar 5, 2025 | 7.5 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
25.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
33.3% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Multi Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.99 | 2 | 6.5 | 0.4% | 0 | 0 |
| 6.95 | 1 | 9.1 | 0.5% | 0 | 0 |
| 6.90 | 4 | 6.7 | 1.9% | 0 | 1 |
| 6.10 | 1 | 7.5 | 1.1% | 0 | 1 |
| 4.5 | 3 | 6.7 | 17.3% | 0 | 3 |
| 4.3 | 2 | 5.5 | 24.0% | 0 | 2 |