druva CVE Vulnerabilities & CVE List (9)

Products (CPE): — CVEs: 9

druva vulnerability overview

Aggregates CVE and security vulnerability intelligence across all druva-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk path handling and vendor risk input validation, with potential vendor impact unexpected behavior and vendor impact file overwrite across vendor surface production workloads use cases.

Vulnerability distribution trend (last 24 months)

Showing 19 of 9 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2021-36668 URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App. [email protected] 7.8 0.56% 2022-07-12 2026-07-08
CVE-2021-36667 Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library. [email protected] 7.8 1.52% 2022-07-12 2026-07-08
CVE-2021-36666 An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission. [email protected] 7.8 0.45% 2022-07-12 2026-07-08
CVE-2021-36665 An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon. [email protected] 7.8 0.46% 2022-07-12 2026-07-08
CVE-2020-5798 inSync Client installer for macOS versions v6.8.0 and prior could allow an attacker to gain privileges of a root user from a lower privileged user due to improper integrity checks and directory permissions. [email protected] 7.8 0.29% 2020-12-07 2026-06-16
CVE-2020-5752 Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges. [email protected] 7.8 8.61% 2020-05-21 2026-06-16
CVE-2019-4001 Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated attacker to execute arbitrary NodeJS code. [email protected] 7.8 0.57% 2020-03-24 2026-06-16
CVE-2019-4000 Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attacker to execute arbitrary Python expressions with root privileges. [email protected] 7.8 0.73% 2020-02-25 2026-06-16
CVE-2019-3999 Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges. [email protected] 7.8 8.57% 2020-02-25 2026-06-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence