Exodus Intelligence
First CVE: Aug 23, 2023Active for: 3 years
37
CVEs Published
More CVEs Published than 51% of tracked CNAs
18.5
Avg CVEs / Year
More Avg CVEs / Year than 65% of tracked CNAs
8.8
Avg CVSS Score
Higher Avg CVSS Score than 97% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Exodus Intelligence over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 23, 2023
2 years ago
Most Recent CVE
Jul 25, 2024
729 days ago
Top CVEs
All CVEs published by Exodus Intelligence as a CNA, regardless of affected vendor or product.
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-23624CRITICAL A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker can exploit this vulnerability to gain command execution on | Jan 26, 2024 | 9.8 | 40 | NO | NO |
CVE-2024-23625CRITICAL A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages. An unauthenticated attacker can exploit this vulnerability to gain comman | Jan 26, 2024 | 9.8 | 38 | NO | NO |
CVE-2024-23621CRITICAL A buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vulnerability to achieve remote code executio | Jan 26, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-23616CRITICAL A buffer overflow vulnerability exists in Symantec Server Management Suite version 7.9 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote cod | Jan 26, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-24621CRITICAL Softaculous Webuzo contains an authentication bypass vulnerability through the password reset functionality. Remote, anonymous attackers can exploit this vulnerability to gain full | Jul 25, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-23626HIGH A command injection vulnerability exists in the ‘SaveSysLogParams’
parameter of the Motorola MR2600. A remote attacker can exploit this
vulnerability to achieve command execution | Jan 26, 2024 | 8.8 | 28 | NO | NO |
CVE-2023-41028HIGH A stack-based buffer overflow exists in Juplink RX4-1500, a WiFi router, in versions 1.0.2 through 1.0.5. An authenticated attacker can exploit this vulnerability to achieve code e | Aug 23, 2023 | 8.8 | 28 | NO | NO |
CVE-2024-23622CRITICAL A stack-based buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vulnerability to achieve remote c | Jan 26, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-23619CRITICAL A hardcoded credential vulnerability exists in IBM Merge Healthcare eFilm Workstation. A remote, unauthenticated attacker can exploit this vulnerability to achieve information disc | Jan 26, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-23615CRITICAL A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code ex | Jan 26, 2024 | 9.8 | 27 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA37 CVEs
68%
32%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local11 (29.7%)
Network26 (70.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low37 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None24 (64.9%)
Unknown0 (0.0%)
Required13 (35.1%)
Privileges Required
Low11 (29.7%)
High0 (0.0%)
None26 (70.3%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (37 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Exodus Intelligence as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Exodus Intelligence as a CNA — matched by CVE ID, not by organization name.