What our NIST NVD record actually says...
One CVE in thirteen years, fixed in forty-eight hours back in 2020, and why you should still go look it up yourself
Editors note: Update, 26 July 2026. This post is from June 2023 and its central claim no longer holds. In May 2026, VulnCheck retroactively assigned CVE-2020-37230 to a bug we fixed in 2020: a local privilege-escalation issue in Syncplify.me Server! 5.0.37, reported by a researcher and patched in v5.1.0 within forty-eight hours. The full account is here: Our first ever CVE. We're correcting this post rather than deleting it. The advice it gives still stands: go check the record yourself. Just read the entries instead of counting them.
In the aftermath of the already infamous MOVEit hack, which is only the most recent one in a long list of competitors exposing their customers data, we would like to take this opportunity to underscore a few important facts about Syncplify Server!
Syncplify Server! has never been breached, and carries a single entry in the NIST NVD, the National Vulnerability Database operated by the National Institute of Standards and Technology. That entry is a local privilege-escalation bug in a 2020 build, fixed within forty-eight hours of being reported. No remotely exploitable vulnerability has ever been recorded against the product.
But hey, it's easy to toss around such a bold claim without proof, right? That's why we're not asking you to take our word for it. This is something you can verify yourself.
How? Here you go:
Point your browser to the NIST NVD website search page
Syncplify Server! or even just Syncplify (direct link). You'll find one entry: CVE-2020-37230. Open it and look at what it actually is. Attack vector Local, class unquoted service path, fixed in 2020.
Now search the platform you're using today. Read the entries, not the counts. A local privilege escalation fixed in two days is a different animal from an unauthenticated remote execution flaw that shipped across multiple major versions.
This is not a random result; where many of our competitors have chosen to give in to flashy UIs and unreasonable support for old/legacy algorithms now obsolete and proven weak, we have never been afraid to lead our customers onto a path of true security without trade-offs.
Stay safe, choose unrelenting security, use Syncplify.
