Netflix, Inc.
First CVE: Jun 21, 2019Active for: 7 years
14
CVEs Published
More CVEs Published than 34% of tracked CNAs
2.8
Avg CVEs / Year
More Avg CVEs / Year than 19% of tracked CNAs
7.9
Avg CVSS Score
Higher Avg CVSS Score than 85% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Netflix, Inc. as a CNA, 71.4% affect products that Netflix, Inc. develops as a vendor.
71.4%
28.6%
Self-reported: 10Third-party: 4
Of all the CVEs published that affect products developed by Netflix, Inc., 62.5% are self-published by Netflix, Inc. as a CNA.
62.5%
37.5%
Self-published: 10Published by other CNAs: 6
Trends Over Time
The number and severity of CVEs published by Netflix, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 21, 2019
7 years ago
Most Recent CVE
Sep 27, 2024
665 days ago
Top CVEs
All CVEs published by Netflix, Inc. as a CNA, regardless of affected vendor or product.
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-4701CRITICAL A path traversal issue potentially leading to remote code execution in Genie for all versions prior to 4.3.18 | May 14, 2024 | 9.9 | 42 | NO | NO |
CVE-2022-27177CRITICAL A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 | Apr 1, 2022 | 9.8 | 32 | NO | NO |
CVE-2020-9297CRITICAL Netflix Titus, all versions prior to version v0.1.1-rc.274, uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messag | Jul 14, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-9296CRITICAL Netflix Titus uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different types of interpolation are suppo | Jun 16, 2020 | 9.8 | 31 | NO | NO |
CVE-2024-7093CRITICAL Dispatch's notification service uses Jinja templates to generate messages to users. Jinja permits code execution within blocks, which were neither properly sanitized nor sandboxed. | Aug 1, 2024 | 9.4 | 26 | NO | NO |
CVE-2024-5023CRITICAL Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Netflix ConsoleMe allows Command Injection.This issue affects ConsoleMe: before | May 16, 2024 | 9.3 | 26 | NO | NO |
CVE-2020-9301HIGH Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within | Dec 11, 2020 | 8.8 | 26 | NO | NO |
CVE-2020-9298HIGH The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially le | Aug 28, 2020 | 7.5 | 25 | NO | NO |
CVE-2019-10028HIGH Denial of Service (DOS) in Dial Reference Source Code Used before June 18th, 2019. | Jun 21, 2019 | 7.5 | 25 | NO | NO |
CVE-2024-9301HIGH A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a | Sep 27, 2024 | 7.5 | 22 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA14 CVEs
29%
29%
43%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (14.3%)
Network12 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (92.9%)
Unknown0 (0.0%)
Required1 (7.1%)
Privileges Required
Low7 (50.0%)
High1 (7.1%)
None6 (42.9%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Netflix, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Netflix, Inc. as a CNA — matched by CVE ID, not by organization name.