Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
insync client vulnerabilities and exploits
(subscribe to this query)
7.8
CVSSv3
CVE-2021-36667
Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows malicious users to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library.
Druva Insync Client
7.8
CVSSv3
CVE-2021-36665
An issue exists in Druva 6.9.0 for macOS, allows malicious users to gain escalated local privileges via the inSyncUpgradeDaemon.
Druva Insync Client
7.8
CVSSv3
CVE-2021-36666
An issue exists in Druva 6.9.0 for MacOS, allows malicious users to gain escalated local privileges via the inSyncDecommission.
Druva Insync Client
7.8
CVSSv3
CVE-2021-36668
URL injection in Driva inSync 6.9.0 for MacOS, allows malicious users to force a visit to an arbitrary url via the port parameter to the Electron App.
Druva Insync Client
7.8
CVSSv3
CVE-2020-5752
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated malicious user to execute arbitrary operating system commands with SYSTEM privileges.
Druva Insync Client 6.6.3
1 Github repository
7.8
CVSSv3
CVE-2019-4001
Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated malicious user to execute arbitrary NodeJS code.
Druva Insync 6.5.0
7.8
CVSSv3
CVE-2019-4000
Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated malicious user to execute arbitrary Python expressions with root privileges.
Druva Insync 6.5.0
7.8
CVSSv3
CVE-2020-5798
inSync Client installer for macOS versions v6.8.0 and prior could allow an malicious user to gain privileges of a root user from a lower privileged user due to improper integrity checks and directory permissions.
Druva Insync 6.8.0
7.8
CVSSv3
CVE-2019-3999
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated malicious user to execute arbitrary operating system commands with SYSTEM privileges.
Druva Insync Client 6.5.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
firmware
CVE-2006-4304
CVE-2024-32878
CVE-2024-31502
XSS
CVE-2024-3059
CVE-2024-33692
CVE-2024-3400
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started