DirectCyber
First CVE: Apr 15, 2024Active for: 2 years
11
CVEs Published
More CVEs Published than 28% of tracked CNAs
11.0
Avg CVEs / Year
More Avg CVEs / Year than 55% of tracked CNAs
8.3
Avg CVSS Score
Higher Avg CVSS Score than 91% of tracked CNAs
9.1%
In CISA KEV
Higher KEV Rate than 98% of tracked CNAs
Trends Over Time
The number and severity of CVEs published by DirectCyber over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 15, 2024
2 years ago
Most Recent CVE
Apr 22, 2024
823 days ago
Top CVEs
All CVEs published by DirectCyber as a CNA, regardless of affected vendor or product.
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-4040CRITICAL A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the | Apr 22, 2024 | 10.0 | 98 | YES | YES |
CVE-2024-29844CRITICAL Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to perform administrative functions. Upon installation or upon f | Apr 15, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-29836CRITICAL The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control, allowing for an unauthenticated attacker to update and a | Apr 15, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-29837HIGH The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attacker to access administrator func | Apr 15, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-3772HIGH Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string. | Apr 15, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-29843HIGH The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on MOBILE_GET_USERS_LIST, allowing for an unauthenticated | Apr 15, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-29842HIGH The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_ABACARD_FIELDS, allowing for an | Apr 15, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-29841HIGH The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_KEYS_FIELDS, allowing for an una | Apr 15, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-29840HIGH The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_PIN_FIELDS, allowing for an unau | Apr 15, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-29838HIGH The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below does not proper sanitize user input, allowing for an unauthenticated attacker to crash the control | Apr 15, 2024 | 7.5 | 21 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA11 CVEs
73%
27%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (90.9%)
Unknown0 (0.0%)
Required1 (9.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None11 (100.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (11 CVEs).
CISA KEV
1 CVE
9.1% of CVEs· 98th percentile
Metasploit
1 CVE
9.1% of CVEs· 98th percentile
Nuclei
1 CVE
9.1% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by DirectCyber as a CNA.
Media Mentions
Media articles that mention a CVE ID published by DirectCyber as a CNA — matched by CVE ID, not by organization name.