JFrog
First CVE: Oct 19, 2021Active for: 5 years
119
CVEs Published
More CVEs Published than 72% of tracked CNAs
19.8
Avg CVEs / Year
More Avg CVEs / Year than 67% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked CNAs
0.8%
In CISA KEV
Higher KEV Rate than 87% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by JFrog as a CNA, 16.0% affect products that JFrog develops as a vendor.
16.0%
84.0%
Self-reported: 19Third-party: 100
Of all the CVEs published that affect products developed by JFrog, 54.3% are self-published by JFrog as a CNA.
54.3%
45.7%
Self-published: 19Published by other CNAs: 16
Trends Over Time
The number and severity of CVEs published by JFrog over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 19, 2021
4 years ago
Most Recent CVE
Jun 18, 2026
36 days ago
Top CVEs
All CVEs published by JFrog as a CNA, regardless of affected vendor or product.
119 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-11953CRITICAL The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS co | Nov 3, 2025 | 9.8 | 93 | YES | NO |
CVE-2025-8943CRITICAL The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inherent authentication and author | Aug 14, 2025 | 9.8 | 87 | NO | YES |
CVE-2025-6514CRITICAL mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL | Jul 9, 2025 | 9.6 | 76 | NO | NO |
CVE-2021-42392CRITICAL The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name | Jan 10, 2022 | 9.8 | 68 | NO | NO |
CVE-2026-1470CRITICAL n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated users during workflow configur | Jan 27, 2026 | 9.9 | 46 | NO | NO |
CVE-2025-55346CRITICAL User-controlled input flows to an unsafe implementation of a dynamic Function constructor, allowing network attackers to run arbitrary unsandboxed JS code in the context of the hos | Aug 14, 2025 | 9.8 | 45 | NO | NO |
CVE-2026-8461HIGH An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote | Jun 18, 2026 | 8.8 | 44 | NO | NO |
CVE-2026-0863CRITICAL Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted Python code in the underlying | Jan 18, 2026 | 9.9 | 41 | NO | NO |
CVE-2024-7340HIGH The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak arbitrary files remote | Jul 31, 2024 | 8.8 | 40 | NO | YES |
CVE-2025-59361CRITICAL The cleanIptables mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers t | Sep 15, 2025 | 9.8 | 36 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA119 CVEs
30%
46%
23%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local7 (5.9%)
Network112 (94.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low100 (84.0%)
High19 (16.0%)
Unknown0 (0.0%)
User Interaction
None98 (82.4%)
Unknown0 (0.0%)
Required21 (17.6%)
Privileges Required
Low31 (26.1%)
High13 (10.9%)
None75 (63.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (119 CVEs).
CISA KEV
1 CVE
0.8% of CVEs· 87th percentile
Metasploit
1 CVE
0.8% of CVEs· 86th percentile
Nuclei
3 CVEs
2.5% of CVEs· 88th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by JFrog as a CNA.
Media Mentions
Media articles that mention a CVE ID published by JFrog as a CNA — matched by CVE ID, not by organization name.