Mend (formerly WhiteSource)
Self-Reporting Analysis
Of all the CVEs published by Mend (formerly WhiteSource) as a CNA, 0.7% affect products that Mend (formerly WhiteSource) develops as a vendor.
Of all the CVEs published that affect products developed by Mend (formerly WhiteSource), 100.0% are self-published by Mend (formerly WhiteSource) as a CNA.
Trends Over Time
The number and severity of CVEs published by Mend (formerly WhiteSource) over time
Top CVEs
All CVEs published by Mend (formerly WhiteSource) as a CNA, regardless of affected vendor or product.
150 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25921MEDIUM In OpenEMR, versions 2.7.3-rc1 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly in the `Allergies` section. An attacker c | Mar 22, 2021 | 5.4 | 67 | NO | NO |
CVE-2022-32174CRITICAL In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover. | Oct 11, 2022 | 9.0 | 60 | NO | NO |
CVE-2021-25919MEDIUM In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly. A highly privileged attacker could inject ar | Mar 22, 2021 | 4.8 | 54 | NO | NO |
CVE-2021-25912CRITICAL Prototype pollution vulnerability in 'dotty' versions 0.0.1 through 0.1.0 allows attackers to cause a denial of service and may lead to remote code execution. | Feb 2, 2021 | 9.8 | 33 | NO | NO |
CVE-2021-25952CRITICAL Prototype pollution vulnerability in ‘just-safe-set’ versions 1.0.0 through 2.2.1 allows an attacker to cause a denial of service and may lead to remote code execution. | Jul 7, 2021 | 9.8 | 32 | NO | NO |
CVE-2021-25943CRITICAL Prototype pollution vulnerability in '101' versions 1.0.0 through 1.6.3 allows an attacker to cause a denial of service and may lead to remote code execution. | May 14, 2021 | 9.8 | 32 | NO | NO |
CVE-2020-28281CRITICAL Prototype pollution vulnerability in 'set-object-value' versions 0.0.0 through 0.0.5 allows an attacker to cause a denial of service and may lead to remote code execution. | Dec 29, 2020 | 9.8 | 32 | NO | NO |
CVE-2022-23066CRITICAL In Solana rBPF versions 0.2.26 and 0.2.27 are affected by Incorrect Calculation which is caused by improper implementation of sdiv instruction. This can lead to the wrong execution | May 9, 2022 | 9.1 | 31 | NO | NO |
CVE-2021-25981CRITICAL In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerable to Insufficient Session Expiration. This may allow an att | Jan 3, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-28273CRITICAL Prototype pollution vulnerability in 'set-in' versions 1.0.0 through 2.0.0 allows attacker to cause a denial of service and may lead to remote code execution. | Dec 2, 2020 | 9.8 | 31 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (150 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Mend (formerly WhiteSource) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Mend (formerly WhiteSource) as a CNA — matched by CVE ID, not by organization name.