HackerOne
First CVE: Nov 3, 2016Active for: 10 years
1,683
CVEs Published
More CVEs Published than 93% of tracked CNAs
153.0
Avg CVEs / Year
More Avg CVEs / Year than 92% of tracked CNAs
7.3
Avg CVSS Score
Higher Avg CVSS Score than 61% of tracked CNAs
1.6%
In CISA KEV
Higher KEV Rate than 90% of tracked CNAs
Trends Over Time
The number and severity of CVEs published by HackerOne over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 3, 2016
9 years ago
Most Recent CVE
Jul 22, 2026
2 days ago
Top CVEs
All CVEs published by HackerOne as a CNA, regardless of affected vendor or product.
1,683 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44529CRITICAL A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody). | Dec 8, 2021 | 9.8 | 99 | YES | YES |
CVE-2019-5418HIGH There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrar | Mar 27, 2019 | 7.5 | 99 | YES | YES |
CVE-2026-34910CRITICAL A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection. | May 22, 2026 | 10.0 | 98 | YES | YES |
CVE-2024-29824HIGH An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. | May 31, 2024 | 8.8 | 98 | YES | YES |
CVE-2024-21893HIGH A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an att | Jan 31, 2024 | 8.2 | 98 | YES | YES |
CVE-2024-21887CRITICAL A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send special | Jan 12, 2024 | 9.1 | 98 | YES | YES |
CVE-2023-46805HIGH An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing co | Jan 12, 2024 | 8.2 | 98 | YES | YES |
CVE-2023-38035CRITICAL A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administra | Aug 21, 2023 | 9.8 | 98 | YES | YES |
CVE-2023-35078CRITICAL An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication. | Jul 25, 2023 | 9.8 | 98 | YES | YES |
CVE-2024-40711CRITICAL A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE). | Sep 7, 2024 | 9.8 | 97 | YES | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA1,683 CVEs
31%
52%
15%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCriticalNone
Attack Vector
Local111 (6.6%)
Network1,523 (90.5%)
Unknown0 (0.0%)
Physical12 (0.7%)
Adjacent Network37 (2.2%)
Attack Complexity
Low1,411 (83.8%)
High272 (16.2%)
Unknown0 (0.0%)
User Interaction
None1,416 (84.1%)
Unknown0 (0.0%)
Required266 (15.8%)
Privileges Required
Low406 (24.1%)
High123 (7.3%)
None1,154 (68.6%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (1683 CVEs).
CISA KEV
27 CVEs
1.6% of CVEs· 90th percentile
Metasploit
16 CVEs
1.0% of CVEs· 87th percentile
Nuclei
34 CVEs
2.0% of CVEs· 86th percentile
ExploitDB
10 CVEs
0.6% of CVEs· 78th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by HackerOne as a CNA.
Media Mentions
Media articles that mention a CVE ID published by HackerOne as a CNA — matched by CVE ID, not by organization name.