STAR Labs SG Pte. Ltd.
First CVE: Apr 17, 2023Active for: 3 years
35
CVEs Published
More CVEs Published than 50% of tracked CNAs
11.7
Avg CVEs / Year
More Avg CVEs / Year than 58% of tracked CNAs
8.3
Avg CVSS Score
Higher Avg CVSS Score than 91% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by STAR Labs SG Pte. Ltd. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 17, 2023
3 years ago
Most Recent CVE
Jun 24, 2026
31 days ago
Top CVEs
All CVEs published by STAR Labs SG Pte. Ltd. as a CNA, regardless of affected vendor or product.
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6782CRITICAL Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution. | Aug 6, 2024 | 9.8 | 88 | NO | YES |
CVE-2023-4220MEDIUM Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to p | Nov 28, 2023 | 6.1 | 84 | NO | YES |
CVE-2023-3368CRITICAL Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutral | Nov 28, 2023 | 9.8 | 77 | NO | YES |
CVE-2024-6781HIGH Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read. | Aug 6, 2024 | 7.5 | 68 | NO | YES |
CVE-2023-30591HIGH Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.startsWith()` or `eventName.toString()`, while processing Socke | Sep 29, 2023 | 7.5 | 51 | NO | NO |
CVE-2023-4197HIGH Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evalua | Nov 1, 2023 | 8.8 | 44 | NO | NO |
CVE-2024-7008MEDIUM Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting. | Aug 6, 2024 | 6.1 | 41 | NO | YES |
CVE-2023-1719CRITICAL Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute | Nov 1, 2023 | 9.8 | 41 | NO | YES |
CVE-2023-1718HIGH
Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated remote attackers to cause denial-of-service via a crafted " | Nov 1, 2023 | 7.5 | 33 | NO | NO |
CVE-2026-9539MEDIUM An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp version before v4.9.2 on hypervisor host environments (e.g. | Jun 24, 2026 | 6.5 | 30 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA35 CVEs
17%
57%
26%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (11.4%)
Network31 (88.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low35 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None24 (68.6%)
Unknown0 (0.0%)
Required11 (31.4%)
Privileges Required
Low18 (51.4%)
High0 (0.0%)
None17 (48.6%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (35 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
5.7% of CVEs· 97th percentile
Nuclei
6 CVEs
17.1% of CVEs· 99th percentile
ExploitDB
1 CVE
2.9% of CVEs· 92nd percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by STAR Labs SG Pte. Ltd. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by STAR Labs SG Pte. Ltd. as a CNA — matched by CVE ID, not by organization name.