Mend (formerly WhiteSource)

First CVE: Nov 10, 2020Active for: 6 years
150
CVEs Published
More CVEs Published than 75% of tracked CNAs
50.0
Avg CVEs / Year
More Avg CVEs / Year than 84% of tracked CNAs
7.1
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Mend (formerly WhiteSource) as a CNA, 0.7% affect products that Mend (formerly WhiteSource) develops as a vendor.

99.3%
Self-reported: 1Third-party: 149

Of all the CVEs published that affect products developed by Mend (formerly WhiteSource), 100.0% are self-published by Mend (formerly WhiteSource) as a CNA.

100.0%
Self-published: 1Published by other CNAs: 0

Trends Over Time

The number and severity of CVEs published by Mend (formerly WhiteSource) over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 10, 2020
5 years ago
Most Recent CVE
Oct 17, 2022
1,376 days ago

Top CVEs

All CVEs published by Mend (formerly WhiteSource) as a CNA, regardless of affected vendor or product.

150 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In OpenEMR, versions 2.7.3-rc1 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly in the `Allergies` section. An attacker c
Mar 22, 20215.467NONO
In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.
Oct 11, 20229.060NONO
In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly. A highly privileged attacker could inject ar
Mar 22, 20214.854NONO
Prototype pollution vulnerability in 'dotty' versions 0.0.1 through 0.1.0 allows attackers to cause a denial of service and may lead to remote code execution.
Feb 2, 20219.833NONO
Prototype pollution vulnerability in ‘just-safe-set’ versions 1.0.0 through 2.2.1 allows an attacker to cause a denial of service and may lead to remote code execution.
Jul 7, 20219.832NONO
Prototype pollution vulnerability in '101' versions 1.0.0 through 1.6.3 allows an attacker to cause a denial of service and may lead to remote code execution.
May 14, 20219.832NONO
Prototype pollution vulnerability in 'set-object-value' versions 0.0.0 through 0.0.5 allows an attacker to cause a denial of service and may lead to remote code execution.
Dec 29, 20209.832NONO
In Solana rBPF versions 0.2.26 and 0.2.27 are affected by Incorrect Calculation which is caused by improper implementation of sdiv instruction. This can lead to the wrong execution
May 9, 20229.131NONO
In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerable to Insufficient Session Expiration. This may allow an att
Jan 3, 20229.831NONO
Prototype pollution vulnerability in 'set-in' versions 1.0.0 through 2.0.0 allows attacker to cause a denial of service and may lead to remote code execution.
Dec 2, 20209.831NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA150 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCriticalUnknown
Attack Vector
Local3 (2.0%)
Network135 (90.0%)
Unknown12 (8.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low137 (91.3%)
High1 (0.7%)
Unknown12 (8.0%)
User Interaction
None64 (42.7%)
Unknown12 (8.0%)
Required74 (49.3%)
Privileges Required
Low53 (35.3%)
High13 (8.7%)
None72 (48.0%)
Unknown12 (8.0%)

Exploit Exposure

Signals from CVEs in this cna scope (150 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Mend (formerly WhiteSource) as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Mend (formerly WhiteSource) as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs