HackerOne

First CVE: Nov 3, 2016Active for: 10 years
1,683
CVEs Published
More CVEs Published than 93% of tracked CNAs
153.0
Avg CVEs / Year
More Avg CVEs / Year than 92% of tracked CNAs
7.3
Avg CVSS Score
Higher Avg CVSS Score than 61% of tracked CNAs
1.6%
In CISA KEV
Higher KEV Rate than 90% of tracked CNAs

Trends Over Time

The number and severity of CVEs published by HackerOne over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 3, 2016
9 years ago
Most Recent CVE
Jul 22, 2026
2 days ago

Top CVEs

All CVEs published by HackerOne as a CNA, regardless of affected vendor or product.

1,683 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
Dec 8, 20219.899YESYES
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrar
Mar 27, 20197.599YESYES
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
May 22, 202610.098YESYES
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
May 31, 20248.898YESYES
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an att
Jan 31, 20248.298YESYES
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send special
Jan 12, 20249.198YESYES
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing co
Jan 12, 20248.298YESYES
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administra
Aug 21, 20239.898YESYES
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
Jul 25, 20239.898YESYES
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
Sep 7, 20249.897YESYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA1,683 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCriticalNone
Attack Vector
Local111 (6.6%)
Network1,523 (90.5%)
Unknown0 (0.0%)
Physical12 (0.7%)
Adjacent Network37 (2.2%)
Attack Complexity
Low1,411 (83.8%)
High272 (16.2%)
Unknown0 (0.0%)
User Interaction
None1,416 (84.1%)
Unknown0 (0.0%)
Required266 (15.8%)
Privileges Required
Low406 (24.1%)
High123 (7.3%)
None1,154 (68.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (1683 CVEs).

CISA KEV
27 CVEs
1.6% of CVEs· 90th percentile
Metasploit
16 CVEs
1.0% of CVEs· 87th percentile
Nuclei
34 CVEs
2.0% of CVEs· 86th percentile
ExploitDB
10 CVEs
0.6% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by HackerOne as a CNA.

Media Mentions

Media articles that mention a CVE ID published by HackerOne as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs