Known Vulnerabilities for products from Synel
Listed below are 8 of the newest known vulnerabilities associated with the vendor "Synel".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-37220 json | Synel Terminals - CWE-494: Download of Code Without Integrity Check | 9.8 - CRITICAL | 2023-09-03 | 2023-09-07 |
| CVE-2023-37213 json | Synel SYnergy Fingerprint Terminals - CWE-78: 'OS Command Injection' | 9.8 - CRITICAL | 2023-07-30 | 2023-08-03 |
| CVE-2023-32227 json | Synel SYnergy Fingerprint Terminals - CWE-798: Use of Hard-coded Credentials | 9.8 - CRITICAL | 2023-07-30 | 2023-08-03 |
| CVE-2022-36778 json | insert HTML / js code inside input how to get to the vulnerable input : Workers > worker nickname > inject in this inpu... | 5.4 - MEDIUM | 2022-09-13 | 2022-09-15 |
| CVE-2022-22791 json | SYNEL - eharmony Authenticated Blind & Stored XSS. Inject JS code into the "comments" field could lead to potential stealing ... | 5.4 - MEDIUM | 2022-01-28 | 2022-02-02 |
| CVE-2022-22790 json | SYNEL - eharmony Directory Traversal. Directory Traversal - is an attack against a server or a Web application aimed at unaut... | 7.5 - HIGH | 2022-01-28 | 2022-02-02 |
| CVE-2021-36718 json | SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report of e... | 6.5 - MEDIUM | 2021-12-08 | 2023-08-08 |
| CVE-2012-2970 json | The Synel SY-780/A Time & Attendance terminal allows remote attackers to cause a denial of service (device hang) via network ... | Not Provided | 2012-07-09 | 2026-04-29 |