Josh Bressers

First CVE: Apr 3, 2017Active for: 9 years
162
CVEs Published
More CVEs Published than 76% of tracked CNAs
81.0
Avg CVEs / Year
More Avg CVEs / Year than 88% of tracked CNAs
7.4
Avg CVSS Score
Higher Avg CVSS Score than 64% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by Josh Bressers over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 3, 2017
9 years ago
Most Recent CVE
Oct 15, 2019
2,474 days ago

Top CVEs

All CVEs published by Josh Bressers as a CNA, regardless of affected vendor or product.

162 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2 does not require an integer identi
Apr 3, 20177.579NOYES
Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_
Jul 19, 20199.833NONO
NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were changed. The attack vector is:
Jul 16, 20199.833NONO
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in the context of TEE core (kernel). The component is: optee_os. The fixed ver
Jul 15, 20199.833NONO
CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attack vector is: Loading an image f
Jul 25, 20199.832NONO
OFFIS.de DCMTK 3.6.3 and below is affected by: Buffer Overflow. The impact is: Possible code execution and confirmed Denial of Service. The component is: DcmRLEDecoder::decompress(
Jul 22, 20199.832NONO
borg-reducer c6d5240 is affected by: Buffer Overflow. The impact is: Possible code execution and denial of service. The component is: Output parameter within the executable.
Jul 15, 20199.832NONO
Slanger 0.6.0 is affected by: Remote Code Execution (RCE). The impact is: A remote attacker can execute arbitrary commands by sending a crafted request to the server. The component
Jul 15, 20199.832NONO
math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution.
Nov 27, 20179.832NONO
perl-CRYPT-JWT 0.022 and earlier is affected by: Incorrect Access Control. The impact is: bypass authentication. The component is: JWT.pm for JWT security token, line 614 in _decod
Jul 25, 20199.831NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA162 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local23 (14.2%)
Network138 (85.2%)
Unknown0 (0.0%)
Physical1 (0.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low160 (98.8%)
High2 (1.2%)
Unknown0 (0.0%)
User Interaction
None99 (61.1%)
Unknown0 (0.0%)
Required63 (38.9%)
Privileges Required
Low20 (12.3%)
High5 (3.1%)
None137 (84.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (162 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.6% of CVEs· 84th percentile
Nuclei
2 CVEs
1.2% of CVEs· 82nd percentile
ExploitDB
1 CVE
0.6% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Josh Bressers as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Josh Bressers as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs