Larry Cashdollar
First CVE: Nov 10, 2016Active for: 10 years
69
CVEs Published
More CVEs Published than 65% of tracked CNAs
8.6
Avg CVEs / Year
More Avg CVEs / Year than 49% of tracked CNAs
8.0
Avg CVSS Score
Higher Avg CVSS Score than 87% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Larry Cashdollar over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 10, 2016
9 years ago
Most Recent CVE
Jan 13, 2026
195 days ago
Top CVEs
All CVEs published by Larry Cashdollar as a CNA, regardless of affected vendor or product.
69 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-9206CRITICAL Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0 | Oct 11, 2018 | 9.8 | 94 | NO | YES |
CVE-2018-9205HIGH Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path. | Apr 4, 2018 | 7.5 | 73 | NO | YES |
CVE-2017-1002000CRITICAL Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authe | Sep 14, 2017 | 9.8 | 54 | NO | YES |
CVE-2017-1002003CRITICAL Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com. | Sep 14, 2017 | 9.8 | 47 | NO | YES |
CVE-2017-1002001CRITICAL Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com. | Sep 14, 2017 | 9.8 | 47 | NO | YES |
CVE-2017-1002008CRITICAL Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not | Sep 14, 2017 | 9.8 | 46 | NO | YES |
CVE-2026-22755CRITICAL Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Vivotek Affected device model numbers are FD8365, FD8365v2, FD9165, FD9171, FD9 | Jan 13, 2026 | 9.3 | 45 | NO | NO |
CVE-2017-1002002CRITICAL Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/ | Sep 14, 2017 | 9.8 | 45 | NO | YES |
CVE-2017-6104HIGH Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0. | Mar 2, 2017 | 7.5 | 39 | NO | YES |
CVE-2018-1002000HIGH There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require administrative privileges to exploit. There is an exploitable | Dec 3, 2018 | 7.2 | 34 | NO | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA69 CVEs
28%
23%
49%
Severity distribution among all CVEs352,727 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (2.9%)
Network67 (97.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low69 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None52 (75.4%)
Unknown0 (0.0%)
Required17 (24.6%)
Privileges Required
Low7 (10.1%)
High11 (15.9%)
None51 (73.9%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (69 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.4% of CVEs· 89th percentile
Nuclei
2 CVEs
2.9% of CVEs· 89th percentile
ExploitDB
18 CVEs
26.1% of CVEs· 100th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Larry Cashdollar as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Larry Cashdollar as a CNA — matched by CVE ID, not by organization name.