STAR Labs SG Pte. Ltd.

First CVE: Apr 17, 2023Active for: 3 years
35
CVEs Published
More CVEs Published than 50% of tracked CNAs
11.7
Avg CVEs / Year
More Avg CVEs / Year than 58% of tracked CNAs
8.3
Avg CVSS Score
Higher Avg CVSS Score than 91% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by STAR Labs SG Pte. Ltd. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 17, 2023
3 years ago
Most Recent CVE
Jun 24, 2026
31 days ago

Top CVEs

All CVEs published by STAR Labs SG Pte. Ltd. as a CNA, regardless of affected vendor or product.

35 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.
Aug 6, 20249.888NOYES
Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to p
Nov 28, 20236.184NOYES
Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutral
Nov 28, 20239.877NOYES
Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read.
Aug 6, 20247.568NOYES
Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.startsWith()` or `eventName.toString()`, while processing Socke
Sep 29, 20237.551NONO
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evalua
Nov 1, 20238.844NONO
Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting.
Aug 6, 20246.141NOYES
Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute
Nov 1, 20239.841NOYES
Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated remote attackers to cause denial-of-service via a crafted "
Nov 1, 20237.533NONO
An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp version before v4.9.2 on hypervisor host environments (e.g.
Jun 24, 20266.530NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA35 CVEs
Severity distribution among all CVEs352,427 CVEs
MediumHighCritical
Attack Vector
Local4 (11.4%)
Network31 (88.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low35 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None24 (68.6%)
Unknown0 (0.0%)
Required11 (31.4%)
Privileges Required
Low18 (51.4%)
High0 (0.0%)
None17 (48.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (35 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
5.7% of CVEs· 97th percentile
Nuclei
6 CVEs
17.1% of CVEs· 99th percentile
ExploitDB
1 CVE
2.9% of CVEs· 92nd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by STAR Labs SG Pte. Ltd. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by STAR Labs SG Pte. Ltd. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs