Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Synapse HIGH 7.8
CVE-2025-9870

Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escala…

Fix: 3.10.730.71519+
Fix from $1,950 2025-10-29
Synapse HIGH 7.8
CVE-2025-9871

Razer Synapse 3 Chroma Connect Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privile…

Fix: 3.10.730.71519+
Fix from $1,950 2025-10-29
Synapse HIGH 7.8
CVE-2025-9869

Razer Synapse 3 Macro Module Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privilege…

Fix: 3.10.730.71519+
Fix from $1,950 2025-10-29
Synapse 4 HIGH 7.8
CVE-2025-27811

A local privilege escalation in the razer_elevation_service.exe in Razer Synapse 4 through 4.0.86.2502180127 allows a local attacker to escalate thei…

Fix: after 4.0.86.2502180127
Fix from $1,950 2025-06-04
Synapse HIGH 7.8
CVE-2022-47631

Razer Synapse through 3.7.1209.121307 allows privilege escalation due to an unsafe installation path and improper privilege management. Attackers can…

Fix: 3.8.0428.042117+
Fix from $1,950 2023-09-14
Razer Central HIGH 7.8
CVE-2023-3513

Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access…

Fix: after 7.11.0.558
Fix from $1,950 2023-07-14
Razer Central HIGH 7.8
CVE-2023-3514

Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access…

Fix: after 7.11.0.558
Fix from $1,950 2023-07-14
Razer Central HIGH 7.8
CVE-2022-45697

Arbitrary File Delete vulnerability in Razer Central before v7.8.0.381 when handling files in the Accounts directory.

Fix: 7.8.0.381+
Fix from $1,950 2023-02-27
Synapse MEDIUM 6.8
CVE-2022-47632

Razer Synapse before 3.7.0830.081906 allows privilege escalation due to an unsafe installation path, improper privilege management, and improper cert…

Fix: 3.7.0830.081906+
Fix from $1,600 2023-01-27
Sila Firmware CRITICAL 9.8
CVE-2022-29013EPSS 77%

A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary commands via a cr…

No fix yet
Fix from $2,300 2022-06-09
Sila Firmware HIGH 7.5
CVE-2022-29014EPSS 11%

A local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary files.

No fix yet
Fix from $1,950 2022-06-09
Synapse HIGH 7.3
CVE-2021-44226

Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\…

Fix: 3.7.0228.022817+
Fix from $1,950 2022-03-23
Synapse MEDIUM 5.5
CVE-2021-30493

Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the ChromaBroadcast s…

No fix yet
Fix from $1,600 2021-04-14
Synapse MEDIUM 5.5
CVE-2021-30494

Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the Razer Chroma SDK …

No fix yet
Fix from $1,600 2021-04-14
Chroma Sdk HIGH 8.1
CVE-2020-16602EPSS 6%

Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in which a file …

Fix: after 3.12.17
Fix from $1,950 2020-09-02
Surround MEDIUM 5.5
CVE-2019-13142

The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user using an executable located …

Mitigation only
Fix from $1,600 2019-07-09
Synapse HIGH 7.8
CVE-2017-14398

rzpnk.sys in Razer Synapse 2.20.15.1104 allows local users to read and write to arbitrary memory locations, and consequently gain privileges, via a m…

Mitigation only
Fix from $1,950 2017-09-13
Synapse HIGH 8.4
CVE-2017-11652

Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the CrashReporter directory, which allows local users to gain privileges via a Troja…

Fix: after 2.20.15.1104
Fix from $1,950 2017-08-18
Synapse HIGH 7.8
CVE-2017-11653

Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the Devices directory, which allows local users to gain privileges via a Trojan hors…

Fix: after 2.20.15.1104
Fix from $1,950 2017-08-18
Synapse CRITICAL 9.8
CVE-2017-9769EPSS 86%

A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpenProcess allowing a handle to…

No fix yet
Fix from $2,300 2017-08-02