DirectCyber

First CVE: Apr 15, 2024Active for: 2 years
11
CVEs Published
More CVEs Published than 28% of tracked CNAs
11.0
Avg CVEs / Year
More Avg CVEs / Year than 55% of tracked CNAs
8.3
Avg CVSS Score
Higher Avg CVSS Score than 91% of tracked CNAs
9.1%
In CISA KEV
Higher KEV Rate than 98% of tracked CNAs

Trends Over Time

The number and severity of CVEs published by DirectCyber over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 15, 2024
2 years ago
Most Recent CVE
Apr 22, 2024
823 days ago

Top CVEs

All CVEs published by DirectCyber as a CNA, regardless of affected vendor or product.

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the
Apr 22, 202410.098YESYES
Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to perform administrative functions. Upon installation or upon f
Apr 15, 20249.827NONO
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control, allowing for an unauthenticated attacker to update and a
Apr 15, 20249.826NONO
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attacker to access administrator func
Apr 15, 20248.824NONO
Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.
Apr 15, 20247.522NONO
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on MOBILE_GET_USERS_LIST, allowing for an unauthenticated
Apr 15, 20247.521NONO
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_ABACARD_FIELDS, allowing for an
Apr 15, 20247.521NONO
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_KEYS_FIELDS, allowing for an una
Apr 15, 20247.521NONO
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_PIN_FIELDS, allowing for an unau
Apr 15, 20247.521NONO
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below does not proper sanitize user input, allowing for an unauthenticated attacker to crash the control
Apr 15, 20247.521NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA11 CVEs
Severity distribution among all CVEs352,294 CVEs
HighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (90.9%)
Unknown0 (0.0%)
Required1 (9.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None11 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (11 CVEs).

CISA KEV
1 CVE
9.1% of CVEs· 98th percentile
Metasploit
1 CVE
9.1% of CVEs· 98th percentile
Nuclei
1 CVE
9.1% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by DirectCyber as a CNA.

Media Mentions

Media articles that mention a CVE ID published by DirectCyber as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs