JFrog

First CVE: Oct 19, 2021Active for: 5 years
119
CVEs Published
More CVEs Published than 72% of tracked CNAs
19.8
Avg CVEs / Year
More Avg CVEs / Year than 67% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked CNAs
0.8%
In CISA KEV
Higher KEV Rate than 87% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by JFrog as a CNA, 16.0% affect products that JFrog develops as a vendor.

16.0%
84.0%
Self-reported: 19Third-party: 100

Of all the CVEs published that affect products developed by JFrog, 54.3% are self-published by JFrog as a CNA.

54.3%
45.7%
Self-published: 19Published by other CNAs: 16

Trends Over Time

The number and severity of CVEs published by JFrog over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 19, 2021
4 years ago
Most Recent CVE
Jun 18, 2026
36 days ago

Top CVEs

All CVEs published by JFrog as a CNA, regardless of affected vendor or product.

119 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS co
Nov 3, 20259.893YESNO
The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inherent authentication and author
Aug 14, 20259.887NOYES
mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL
Jul 9, 20259.676NONO
The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name
Jan 10, 20229.868NONO
n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated users during workflow configur
Jan 27, 20269.946NONO
User-controlled input flows to an unsafe implementation of a dynamic Function constructor, allowing network attackers to run arbitrary unsandboxed JS code in the context of the hos
Aug 14, 20259.845NONO
An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote
Jun 18, 20268.844NONO
Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted Python code in the underlying
Jan 18, 20269.941NONO
The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak arbitrary files remote
Jul 31, 20248.840NOYES
The cleanIptables mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers t
Sep 15, 20259.836NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA119 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local7 (5.9%)
Network112 (94.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low100 (84.0%)
High19 (16.0%)
Unknown0 (0.0%)
User Interaction
None98 (82.4%)
Unknown0 (0.0%)
Required21 (17.6%)
Privileges Required
Low31 (26.1%)
High13 (10.9%)
None75 (63.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (119 CVEs).

CISA KEV
1 CVE
0.8% of CVEs· 87th percentile
Metasploit
1 CVE
0.8% of CVEs· 86th percentile
Nuclei
3 CVEs
2.5% of CVEs· 88th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by JFrog as a CNA.

Media Mentions

Media articles that mention a CVE ID published by JFrog as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs