Salesforce, Inc.

First CVE: Aug 30, 2019Active for: 7 years
45
CVEs Published
More CVEs Published than 55% of tracked CNAs
7.5
Avg CVEs / Year
More Avg CVEs / Year than 45% of tracked CNAs
7.9
Avg CVSS Score
Higher Avg CVSS Score than 85% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Salesforce, Inc. as a CNA, 33.3% affect products that Salesforce, Inc. develops as a vendor.

33.3%
66.7%
Self-reported: 15Third-party: 30

Of all the CVEs published that affect products developed by Salesforce, Inc., 75.0% are self-published by Salesforce, Inc. as a CNA.

75.0%
25.0%
Self-published: 15Published by other CNAs: 5

Trends Over Time

The number and severity of CVEs published by Salesforce, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 30, 2019
6 years ago
Most Recent CVE
Mar 23, 2026
123 days ago

Top CVEs

All CVEs published by Salesforce, Inc. as a CNA, regardless of affected vendor or product.

45 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (CloudPagesUrl module) allows Web Services
Jan 24, 20269.834NONO
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (MicrositeUrl module) allows Web Services
Jan 24, 20269.834NONO
Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Web
Jan 24, 20269.833NONO
Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code in Non-Executable Files.This i
Jan 9, 20269.833NONO
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Upload modules) allows Local Code
Aug 22, 20259.333NONO
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub
Jan 24, 20269.831NONO
Uncontrolled Search Path Element vulnerability in Salesforce Salesforce CLI on Windows allows Replace Trusted Executable.This issue affects Salesforce CLI: before 2.106.6.
Sep 23, 20258.830NONO
Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow remote code execution.Tableau only
Oct 17, 20229.830NONO
MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Affect
Mar 26, 20219.830NONO
MuleSoft is aware of a Remote Code Execution vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Versions a
Mar 26, 20219.830NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA45 CVEs
Severity distribution among all CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local1 (2.2%)
Network41 (91.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (6.7%)
Attack Complexity
Low43 (95.6%)
High2 (4.4%)
Unknown0 (0.0%)
User Interaction
None41 (91.1%)
Unknown0 (0.0%)
Required4 (8.9%)
Privileges Required
Low7 (15.6%)
High1 (2.2%)
None37 (82.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (45 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Salesforce, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Salesforce, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs