Fluid Attacks

First CVE: Jan 10, 2022Active for: 5 years
327
CVEs Published
More CVEs Published than 84% of tracked CNAs
65.4
Avg CVEs / Year
More Avg CVEs / Year than 86% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked CNAs
0.3%
In CISA KEV
Higher KEV Rate than 82% of tracked CNAs

Trends Over Time

The number and severity of CVEs published by Fluid Attacks over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 10, 2022
4 years ago
Most Recent CVE
Jul 17, 2026
7 days ago

Top CVEs

All CVEs published by Fluid Attacks as a CNA, regardless of affected vendor or product.

327 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security se
Jun 20, 20238.880YESNO
ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?cmd=connect' by obtaining a valid SID without any kind of au
Apr 18, 202210.051NOYES
Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization.
Feb 20, 20249.849NONO
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php
Jan 19, 20227.248NOYES
A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled. This issue a
Feb 27, 20269.839NONO
An unauthenticated user with write access to the knowledge base can store an XSS payload in a knowledge base item. This issue affects glpi: before 11.0.7.
Jun 2, 20268.436NONO
osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem.
Jul 17, 20267.132NONO
A vulnerability in the quarantine and restore workflow of the X-VPN macOS website versions 77.0 through 77.5 allow a local attacker to leverage a race condition and symlink manipul
Jun 9, 20267.332NONO
Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate
Nov 25, 20229.832NONO
CandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application applicati
Nov 3, 20226.132NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA327 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local34 (10.4%)
Network286 (87.5%)
Unknown0 (0.0%)
Physical6 (1.8%)
Adjacent Network0 (0.0%)
Attack Complexity
Low322 (98.5%)
High5 (1.5%)
Unknown0 (0.0%)
User Interaction
None187 (57.2%)
Unknown0 (0.0%)
Required116 (35.5%)
Privileges Required
Low147 (45.0%)
High28 (8.6%)
None152 (46.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (327 CVEs).

CISA KEV
1 CVE
0.3% of CVEs· 82nd percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
5 CVEs
1.5% of CVEs· 83rd percentile
ExploitDB
1 CVE
0.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Fluid Attacks as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Fluid Attacks as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs