Known vulnerabilities in Apache Syncope 3.0.0-M0

Version: 3.0.0-M0
Software CPE: cpe:2.3:a:apache_foundation:syncope:*:*:*:*:*:*:*:*
Total vulnerabilities: 28
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Apache Syncope version 3.0.0-M0 Apache Syncope 3.0.0-M0 is affected by 28 vulnerabilities: 1 high, 2 medium, 25 low Critical High Medium Low

Vulnerabilities (28)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU150211 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-77147
CWE-94 Low
No
No
4.0.8, 4.1.3 16.09.2026 SB2026091562
#VU149998 - Improper Verification of Cryptographic Signature
CVE-2026-87802
CWE-347 High
No
No
4.0.8, 4.1.3 15.09.2026 SB2026091562
#VU149997 - Improper Authentication
CVE-2026-87785
CWE-287 Low
No
No
4.0.8, 4.1.3 15.09.2026 SB2026091562
#VU149995 - Improper Neutralization of Special Elements in Data Query Logic
CVE-2026-86460
CWE-943 Low
No
No
4.0.8, 4.1.3 15.09.2026 SB2026091562
#VU149994 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-82232
CWE-89 Low
No
No
4.0.8, 4.1.3 15.09.2026 SB2026091562
#VU149993 - Insertion of Sensitive Information Into Sent Data
CVE-2026-78336
CWE-201 Low
No
No
4.0.8, 4.1.3 15.09.2026 SB2026091562
#VU149992 - Improper Privilege Management
CVE-2026-78330
CWE-269 Low
No
No
4.0.8, 4.1.3 15.09.2026 SB2026091562
#VU149990 - Incomplete List of Disallowed Inputs
CVE-2026-77883
CWE-184 Low
No
No
4.0.8, 4.1.3 15.09.2026 SB2026091562
#VU149989 - Incorrect Authorization
CVE-2026-77181
CWE-863 Low
No
No
4.0.8, 4.1.3 15.09.2026 SB2026091562
#VU149988 - Missing Authorization
CVE-2026-75030
CWE-862 Low
No
No
4.0.8, 4.1.3 15.09.2026 SB2026091562
#VU149987 - Insufficiently Protected Credentials
CVE-2026-75015
CWE-522 Low
No
No
4.0.8, 4.1.3 15.09.2026 SB2026091562
#VU149986 - Incorrect Authorization
CVE-2026-73668
CWE-863 Low
No
No
4.0.8, 4.1.3 15.09.2026 SB2026091562
#VU149985 - Incorrect Authorization
CVE-2026-73579
CWE-863 Low
No
No
4.0.8, 4.1.3 15.09.2026 SB2026091562
#VU149984 - Improper Privilege Management
CVE-2026-73470
CWE-269 Low
No
No
4.0.8, 4.1.3 15.09.2026 SB2026091562
#VU149983 - Exposure of sensitive information to an unauthorized actor
CVE-2026-73178
CWE-200 Low
No
No
4.0.8, 4.1.3 15.09.2026 SB2026091562
#VU149982 - Incorrect Authorization
CVE-2026-73370
CWE-863 Low
No
No
4.0.8, 4.1.3 15.09.2026 SB2026091562
#VU149981 - Incorrect Authorization
CVE-2026-73236
CWE-863 Low
No
No
4.0.8, 4.1.3 15.09.2026 SB2026091562
#VU149980 - Improper Neutralization of Formula Elements in a CSV File
CVE-2026-73195
CWE-1236 Low
No
No
4.0.8, 4.1.3 15.09.2026 SB2026091562
#VU149979 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2026-73191
CWE-601 Medium
No
No
4.0.8, 4.1.3 15.09.2026 SB2026091562
#VU149978 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-77051
CWE-89 Low
No
No
4.0.8, 4.1.3 15.09.2026 SB2026091562


Showing elements 1 - 20 out of 28