CyberArk Labs
First CVE: Dec 15, 2024Active for: 2 years
5
CVEs Published
More CVEs Published than 15% of tracked CNAs
2.5
Avg CVEs / Year
More Avg CVEs / Year than 16% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by CyberArk Labs as a CNA, 0.0% affect products that CyberArk Labs develops as a vendor.
100.0%
Self-reported: 0Third-party: 5
Of all the CVEs published that affect products developed by CyberArk Labs, 0.0% are self-published by CyberArk Labs as a CNA.
100.0%
Self-published: 0Published by other CNAs: 31
Trends Over Time
The number and severity of CVEs published by CyberArk Labs over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 15, 2024
19 months ago
Most Recent CVE
Sep 1, 2025
326 days ago
Top CVEs
All CVEs published by CyberArk Labs as a CNA, regardless of affected vendor or product.
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8854CRITICAL Stack-based buffer overflow in LoadOFF in bulletphysics bullet3 before 3.26 on all platforms allows remote attackers to execute arbitrary code via a crafted OFF file with an overlo | Aug 11, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-9809CRITICAL Out-of-bounds write in cdfs_open_cue_track in libretro libretro-common latest on all platforms allows remote attackers to execute arbitrary code via a crafted .cue file with a file | Sep 1, 2025 | 9.8 | 31 | NO | NO |
CVE-2024-7701HIGH Use of Password Hash With Insufficient Computational Effort vulnerability in percona percona-toolkit allows Encryption Brute Forcing.This issue affects percona-toolkit: 3.6.0. | Dec 15, 2024 | 7.5 | 22 | NO | NO |
CVE-2025-9810MEDIUM TOCTOU in linenoiseHistorySave in linenoise allows local attackers to overwrite arbitrary files and change permissions via a symlink race between fopen("w") on the history path an | Sep 1, 2025 | 5.8 | 21 | NO | NO |
CVE-2025-0518MEDIUM Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files https: | Jan 16, 2025 | 5.3 | 17 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA5 CVEs
40%
20%
40%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (20.0%)
Network4 (80.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (80.0%)
High1 (20.0%)
Unknown0 (0.0%)
User Interaction
None5 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (20.0%)
High0 (0.0%)
None4 (80.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by CyberArk Labs as a CNA.
Media Mentions
Media articles that mention a CVE ID published by CyberArk Labs as a CNA — matched by CVE ID, not by organization name.