Disclosures
Every vulnerability Syntetisk has disclosed, tracked with an internal SYNT- advisory ID — vendor, severity, and CVE status at a glance.
| ID | Date | Vendor | Title | Severity | CVE |
|---|---|---|---|---|---|
| SYNT-2026-003 | Lima | Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657) | High | CVE-2026-53657 | |
| SYNT-2026-002 | phpBB | Blind POST SSRF in phpBB 4.0.0-alpha1 Web Push (CVD with phpBB) | Medium | None assigned | |
| SYNT-2026-001 | AWS | Empty-ciphertext panic in aws-encryption-provider (CVD with AWS) | Medium | None assigned |