Fluid Attacks
First CVE: Jan 10, 2022Active for: 5 years
327
CVEs Published
More CVEs Published than 84% of tracked CNAs
65.4
Avg CVEs / Year
More Avg CVEs / Year than 86% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked CNAs
0.3%
In CISA KEV
Higher KEV Rate than 82% of tracked CNAs
Trends Over Time
The number and severity of CVEs published by Fluid Attacks over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 10, 2022
4 years ago
Most Recent CVE
Jul 17, 2026
7 days ago
Top CVEs
All CVEs published by Fluid Attacks as a CNA, regardless of affected vendor or product.
327 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2533HIGH A Cross-Site Request Forgery (CSRF) vulnerability has been identified in
PaperCut NG/MF, which, under specific conditions, could potentially enable
an attacker to alter security se | Jun 20, 2023 | 8.8 | 80 | YES | NO |
CVE-2022-25226CRITICAL ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?cmd=connect' by obtaining a valid SID without any kind of au | Apr 18, 2022 | 10.0 | 51 | NO | YES |
CVE-2024-1651CRITICAL Torrentpier version 2.4.1 allows executing arbitrary commands on the server.
This is possible because the application is vulnerable to insecure deserialization.
| Feb 20, 2024 | 9.8 | 49 | NO | NO |
CVE-2022-23046HIGH PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php | Jan 19, 2022 | 7.2 | 48 | NO | YES |
CVE-2026-2293CRITICAL A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled.
This issue a | Feb 27, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-5385HIGH An unauthenticated user with write access to the knowledge base can store an XSS payload in a knowledge base item.
This issue affects glpi: before 11.0.7. | Jun 2, 2026 | 8.4 | 36 | NO | NO |
CVE-2026-14871HIGH osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem. | Jul 17, 2026 | 7.1 | 32 | NO | NO |
CVE-2026-2638HIGH A vulnerability in the quarantine and restore workflow of the X-VPN macOS website versions 77.0 through 77.5 allow a local attacker to leverage a race condition and symlink manipul | Jun 9, 2026 | 7.3 | 32 | NO | NO |
CVE-2022-41705CRITICAL Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate | Nov 25, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-42749MEDIUM CandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application applicati | Nov 3, 2022 | 6.1 | 32 | NO | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA327 CVEs
52%
24%
24%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local34 (10.4%)
Network286 (87.5%)
Unknown0 (0.0%)
Physical6 (1.8%)
Adjacent Network0 (0.0%)
Attack Complexity
Low322 (98.5%)
High5 (1.5%)
Unknown0 (0.0%)
User Interaction
None187 (57.2%)
Unknown0 (0.0%)
Required116 (35.5%)
Privileges Required
Low147 (45.0%)
High28 (8.6%)
None152 (46.5%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (327 CVEs).
CISA KEV
1 CVE
0.3% of CVEs· 82nd percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
5 CVEs
1.5% of CVEs· 83rd percentile
ExploitDB
1 CVE
0.3% of CVEs· 75th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Fluid Attacks as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Fluid Attacks as a CNA — matched by CVE ID, not by organization name.