Pentraze Cybersecurity
First CVE: Apr 10, 2024Active for: 2 years
13
CVEs Published
More CVEs Published than 31% of tracked CNAs
4.3
Avg CVEs / Year
More Avg CVEs / Year than 29% of tracked CNAs
8.0
Avg CVSS Score
Higher Avg CVSS Score than 87% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Pentraze Cybersecurity over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 10, 2024
2 years ago
Most Recent CVE
Feb 19, 2026
155 days ago
Top CVEs
All CVEs published by Pentraze Cybersecurity as a CNA, regardless of affected vendor or product.
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-3120CRITICAL A stack-buffer overflow vulnerability exists in all versions of sngrep since v1.4.1. The flaw is due to inadequate bounds checking when copying 'Content-Length' and 'Warning' heade | Apr 10, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-1244CRITICAL Improper input validation in the OSSEC HIDS agent for Windows prior to version 3.8.0 allows an attacker in with control over the OSSEC server or in possession of the agent's key to | Jun 11, 2025 | 9.5 | 27 | NO | NO |
CVE-2024-0916CRITICAL Unauthenticated file upload allows remote code execution.
This issue affects UvDesk Community: from 1.0.0 through 1.1.3.
| Apr 25, 2024 | 10.0 | 27 | NO | NO |
CVE-2024-3119CRITICAL A buffer overflow vulnerability exists in all versions of sngrep since v0.4.2, due to improper handling of 'Call-ID' and 'X-Call-ID' SIP headers. The functions sip_get_callid and s | Apr 10, 2024 | 9.8 | 27 | NO | NO |
CVE-2025-4960HIGH The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege escalation vulnerability due to multiple flaws in its implementa | Feb 19, 2026 | 7.8 | 24 | NO | NO |
CVE-2024-7062HIGH Nimble Commander suffers from a privilege escalation vulnerability due to the server (info.filesmanager.Files.PrivilegedIOHelperV2) performing improper/insufficient validation of a | Jul 26, 2024 | 7.8 | 23 | NO | NO |
CVE-2024-9062HIGH The Archify application contains a local privilege escalation vulnerability due to insufficient client validation in its privileged helper tool, com.oct4pie.archifyhelper, which is | Jun 11, 2025 | 7.8 | 21 | NO | NO |
CVE-2024-7457HIGH The ws.stash.app.mac.daemon.helper tool contains a vulnerability caused by an incorrect use of macOS’s authorization model. Instead of validating the client's authorization referen | Jun 11, 2025 | 7.8 | 21 | NO | NO |
CVE-2024-8272HIGH The com.uaudio.bsd.helper service, responsible for handling privileged operations, fails to implement critical client validation during XPC inter-process communication (IPC). Speci | Nov 25, 2024 | 7.8 | 21 | NO | NO |
CVE-2024-7915HIGH The application Sensei Mac Cleaner contains a local privilege escalation vulnerability, allowing an attacker to perform multiple operations as the root user. These operations inclu | Nov 25, 2024 | 7.8 | 21 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA13 CVEs
15%
54%
31%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local8 (61.5%)
Network5 (38.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (84.6%)
High2 (15.4%)
Unknown0 (0.0%)
User Interaction
None13 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low8 (61.5%)
High1 (7.7%)
None4 (30.8%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Pentraze Cybersecurity as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Pentraze Cybersecurity as a CNA — matched by CVE ID, not by organization name.