Netflix, Inc.

First CVE: Jun 21, 2019Active for: 7 years
14
CVEs Published
More CVEs Published than 34% of tracked CNAs
2.8
Avg CVEs / Year
More Avg CVEs / Year than 19% of tracked CNAs
7.9
Avg CVSS Score
Higher Avg CVSS Score than 85% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Netflix, Inc. as a CNA, 71.4% affect products that Netflix, Inc. develops as a vendor.

71.4%
28.6%
Self-reported: 10Third-party: 4

Of all the CVEs published that affect products developed by Netflix, Inc., 62.5% are self-published by Netflix, Inc. as a CNA.

62.5%
37.5%
Self-published: 10Published by other CNAs: 6

Trends Over Time

The number and severity of CVEs published by Netflix, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 21, 2019
7 years ago
Most Recent CVE
Sep 27, 2024
665 days ago

Top CVEs

All CVEs published by Netflix, Inc. as a CNA, regardless of affected vendor or product.

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A path traversal issue potentially leading to remote code execution in Genie for all versions prior to 4.3.18
May 14, 20249.942NONO
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2
Apr 1, 20229.832NONO
Netflix Titus, all versions prior to version v0.1.1-rc.274, uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messag
Jul 14, 20209.831NONO
Netflix Titus uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different types of interpolation are suppo
Jun 16, 20209.831NONO
Dispatch's notification service uses Jinja templates to generate messages to users. Jinja permits code execution within blocks, which were neither properly sanitized nor sandboxed.
Aug 1, 20249.426NONO
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Netflix ConsoleMe allows Command Injection.This issue affects ConsoleMe: before
May 16, 20249.326NONO
Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within
Dec 11, 20208.826NONO
The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially le
Aug 28, 20207.525NONO
Denial of Service (DOS) in Dial Reference Source Code Used before June 18th, 2019.
Jun 21, 20197.525NONO
A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a
Sep 27, 20247.522NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA14 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local2 (14.3%)
Network12 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (92.9%)
Unknown0 (0.0%)
Required1 (7.1%)
Privileges Required
Low7 (50.0%)
High1 (7.1%)
None6 (42.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Netflix, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Netflix, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs