CPAN Security Group

First CVE: Mar 11, 2025Active for: 1 year
257
CVEs Published
More CVEs Published than 82% of tracked CNAs
128.5
Avg CVEs / Year
More Avg CVEs / Year than 91% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by CPAN Security Group over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 11, 2025
16 months ago
Most Recent CVE
Jul 22, 2026
2 days ago

Top CVEs

All CVEs published by CPAN Security Group as a CNA, regardless of affected vendor or product.

257 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates i
Jul 14, 20269.843NONO
Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX
Jul 13, 20269.843NONO
DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough m
Jul 7, 20269.842NONO
Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an E
Jul 20, 20269.841NONO
Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cr
Jul 20, 20269.841NONO
Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_stud
Jul 13, 20269.141NONO
Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded. Module names starting with "::" could be passed to the load function to specify ar
Jul 7, 20269.841NONO
HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the <template> element was added to libgumbo 0.10.0 in 2015, but the walk_tree funct
Jul 1, 20269.841NONO
DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers. The default SQL builder, a SQL::Abstract subclass, sets bindtype in its construc
Jun 30, 20269.841NONO
GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. GD::Image::_make_filehandle opens a fi
Jun 14, 20269.841NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA257 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCriticalUnknown
Attack Vector
Local33 (12.8%)
Network220 (85.6%)
Unknown3 (1.2%)
Physical0 (0.0%)
Adjacent Network1 (0.4%)
Attack Complexity
Low242 (94.2%)
High12 (4.7%)
Unknown3 (1.2%)
User Interaction
None238 (92.6%)
Unknown3 (1.2%)
Required16 (6.2%)
Privileges Required
Low23 (8.9%)
High0 (0.0%)
None231 (89.9%)
Unknown3 (1.2%)

Exploit Exposure

Signals from CVEs in this cna scope (257 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by CPAN Security Group as a CNA.

Media Mentions

Media articles that mention a CVE ID published by CPAN Security Group as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs