Mandiant Inc.

First CVE: Dec 24, 2023Active for: 3 years
18
CVEs Published
More CVEs Published than 37% of tracked CNAs
4.5
Avg CVEs / Year
More Avg CVEs / Year than 30% of tracked CNAs
8.6
Avg CVSS Score
Higher Avg CVSS Score than 95% of tracked CNAs
11.1%
In CISA KEV
Higher KEV Rate than 98% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Mandiant Inc. as a CNA, 0.0% affect products that Mandiant Inc. develops as a vendor.

100.0%
Self-reported: 0Third-party: 18

Of all the CVEs published that affect products developed by Mandiant Inc., 0.0% are self-published by Mandiant Inc. as a CNA.

100.0%
Self-published: 0Published by other CNAs: 3

Trends Over Time

The number and severity of CVEs published by Mandiant Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 24, 2023
2 years ago
Most Recent CVE
Apr 16, 2026
99 days ago

Top CVEs

All CVEs published by Mandiant Inc. as a CNA, regardless of affected vendor or product.

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.
Nov 10, 20259.197YESYES
Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to
Dec 24, 20237.881YESYES
Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Applian
Dec 24, 20239.867NOYES
Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanism
Apr 16, 20269.136NONO
WordPress plugin Contact Form CFDB7 versions up to and including 1.3.2 are affected by a pre-authentication SQL injection vulnerability that cascades into insecure deserialization
Oct 29, 20259.633NONO
Lightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and share dashboards. A dashboard that contains HTML elements whi
Aug 30, 20247.332NOYES
Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user input in a web application endpoint. An attacker can supply
Jan 28, 202610.030NONO
Explorance Blue versions prior to 8.14.13 contain an authenticated remote file download vulnerability in a web service component. In default configurations, this flaw can be levera
Jan 28, 20269.929NONO
Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated
Feb 1, 20249.829NONO
Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administrative interface. The application does not adequately restri
Jan 28, 20269.127NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA18 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local2 (11.1%)
Network16 (88.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (94.4%)
High1 (5.6%)
Unknown0 (0.0%)
User Interaction
None14 (77.8%)
Unknown0 (0.0%)
Required4 (22.2%)
Privileges Required
Low4 (22.2%)
High3 (16.7%)
None11 (61.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (18 CVEs).

CISA KEV
2 CVEs
11.1% of CVEs· 98th percentile
Metasploit
2 CVEs
11.1% of CVEs· 99th percentile
Nuclei
2 CVEs
11.1% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Mandiant Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Mandiant Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs