Ping Identity Corporation

First CVE: Aug 18, 2021Active for: 5 years
49
CVEs Published
More CVEs Published than 57% of tracked CNAs
8.2
Avg CVEs / Year
More Avg CVEs / Year than 48% of tracked CNAs
6.6
Avg CVSS Score
Higher Avg CVSS Score than 27% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Ping Identity Corporation as a CNA, 85.7% affect products that Ping Identity Corporation develops as a vendor.

85.7%
14.3%
Self-reported: 42Third-party: 7

Of all the CVEs published that affect products developed by Ping Identity Corporation, 87.5% are self-published by Ping Identity Corporation as a CNA.

87.5%
12.5%
Self-published: 42Published by other CNAs: 6

Trends Over Time

The number and severity of CVEs published by Ping Identity Corporation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 18, 2021
4 years ago
Most Recent CVE
Jun 12, 2026
42 days ago

Top CVEs

All CVEs published by Ping Identity Corporation as a CNA, regardless of affected vendor or product.

49 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposure. An attacker capable of exploiting this vulnerability may
Apr 30, 20229.931NONO
The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.
Sep 27, 20219.830NONO
Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.
Feb 6, 20249.827NONO
The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF) through crafted GET requests.
Apr 25, 20238.827NONO
The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The server advances the authentication state without verifying the O
Dec 4, 20258.626NONO
A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS c
Oct 25, 20239.826NONO
Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and cop
Jun 12, 20266.325NONO
Relative Path Traversal vulnerability in Ping Identity PingAM Java Policy Agent allows Parameter Injection.This issue affects PingAM Java Policy Agent: through 5.10.3, through 2023
Feb 20, 20259.125NONO
HTTP request desynchronization in Ping Identity PingAccess, all versions prior to 8.0.1 affected allows an attacker to send specially crafted http header requests to create a reque
May 31, 20248.825NONO
Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter
Oct 25, 20239.825NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA49 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCriticalNone
Attack Vector
Local7 (14.3%)
Network39 (79.6%)
Unknown0 (0.0%)
Physical2 (4.1%)
Adjacent Network1 (2.0%)
Attack Complexity
Low39 (79.6%)
High10 (20.4%)
Unknown0 (0.0%)
User Interaction
None39 (79.6%)
Unknown0 (0.0%)
Required3 (6.1%)
Privileges Required
Low23 (46.9%)
High8 (16.3%)
None18 (36.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (49 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Ping Identity Corporation as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Ping Identity Corporation as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs