Mandiant Inc.
First CVE: Dec 24, 2023Active for: 3 years
18
CVEs Published
More CVEs Published than 37% of tracked CNAs
4.5
Avg CVEs / Year
More Avg CVEs / Year than 30% of tracked CNAs
8.6
Avg CVSS Score
Higher Avg CVSS Score than 95% of tracked CNAs
11.1%
In CISA KEV
Higher KEV Rate than 98% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by Mandiant Inc. as a CNA, 0.0% affect products that Mandiant Inc. develops as a vendor.
100.0%
Self-reported: 0Third-party: 18
Of all the CVEs published that affect products developed by Mandiant Inc., 0.0% are self-published by Mandiant Inc. as a CNA.
100.0%
Self-published: 0Published by other CNAs: 3
Trends Over Time
The number and severity of CVEs published by Mandiant Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 24, 2023
2 years ago
Most Recent CVE
Apr 16, 2026
99 days ago
Top CVEs
All CVEs published by Mandiant Inc. as a CNA, regardless of affected vendor or product.
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-12480CRITICAL Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete. | Nov 10, 2025 | 9.1 | 97 | YES | YES |
CVE-2023-7101HIGH Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to | Dec 24, 2023 | 7.8 | 81 | YES | YES |
CVE-2023-7102CRITICAL Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Applian | Dec 24, 2023 | 9.8 | 67 | NO | YES |
CVE-2026-5426CRITICAL Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanism | Apr 16, 2026 | 9.1 | 36 | NO | NO |
CVE-2025-4665CRITICAL WordPress plugin Contact Form CFDB7 versions up to and including 1.3.2 are affected by a pre-authentication SQL injection vulnerability that cascades into insecure deserialization | Oct 29, 2025 | 9.6 | 33 | NO | NO |
CVE-2024-6586HIGH Lightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and share dashboards. A dashboard that contains HTML elements whi | Aug 30, 2024 | 7.3 | 32 | NO | YES |
CVE-2025-57792CRITICAL Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user input in a web application endpoint. An attacker can supply | Jan 28, 2026 | 10.0 | 30 | NO | NO |
CVE-2025-57795CRITICAL Explorance Blue versions prior to 8.14.13 contain an authenticated remote file download vulnerability in a web service component. In default configurations, this flaw can be levera | Jan 28, 2026 | 9.9 | 29 | NO | NO |
CVE-2023-4472CRITICAL Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated | Feb 1, 2024 | 9.8 | 29 | NO | NO |
CVE-2025-57794CRITICAL Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administrative interface. The application does not adequately restri | Jan 28, 2026 | 9.1 | 27 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA18 CVEs
17%
28%
56%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (11.1%)
Network16 (88.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (94.4%)
High1 (5.6%)
Unknown0 (0.0%)
User Interaction
None14 (77.8%)
Unknown0 (0.0%)
Required4 (22.2%)
Privileges Required
Low4 (22.2%)
High3 (16.7%)
None11 (61.1%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (18 CVEs).
CISA KEV
2 CVEs
11.1% of CVEs· 98th percentile
Metasploit
2 CVEs
11.1% of CVEs· 99th percentile
Nuclei
2 CVEs
11.1% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Mandiant Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Mandiant Inc. as a CNA — matched by CVE ID, not by organization name.