Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Activewebsoftwares

First CVE: Apr 6, 2005Active for: 21 yearsTotal CVEs: 36
52.5
VTI Score
TOP TARGET

Activewebsoftwares maintains a focused portfolio of web-based business and e-commerce applications including bidding platforms, pricing tools, business directories, and webmail systems, which occupy a notable niche in the vulnerability landscape despite a small product count. The vendor's disclosures center durably on application-layer input-handling and output-encoding weaknesses—SQL injection, cross-site scripting, and sensitive information exposure—that are characteristic of web applications built without memory-safety constraints. The vulnerability set shows a strong tendency toward public exploit availability, reflecting the straightforward attack surface and tooling maturity of web-application flaws in general. Defenders should treat this vendor's advisories as relevant to web-application exposure tiers and apply input-validation and output-encoding hardening across dependent systems; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
36
Total CVEs
More Total CVEs than 97% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Activewebsoftwares over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 6, 2005
21 years ago
Most Recent CVE
Jun 21, 2010
5,878 days ago

Products(18 total)

Top CVEs

Signals from CVEs in this vendor scope (36 CVEs).

36 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2010-2359HIGH
SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizType parameter, a different v
Jun 21, 20107.532NOYES
CVE-2008-5975HIGH
SQL injection vulnerability in links.asp in Active Price Comparison 4.0 allows remote attackers to execute arbitrary SQL commands via the linkid parameter. NOTE: the provenance of
Jan 27, 20097.529NOYES
CVE-2005-1029HIGH
Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) SortDir, or (3) Sortby parameter to d
Apr 6, 20057.529NOYES
CVE-2009-4437HIGH
Multiple SQL injection vulnerabilities in Active Auction House 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to wishlist.asp and the (2)
Dec 28, 20097.528NOYES
CVE-2009-4436HIGH
Multiple SQL injection vulnerabilities in Active Web Softwares eWebquiz 8 allow remote attackers to execute arbitrary SQL commands via the QuizID parameter to (1) questions.asp, (2
Dec 28, 20097.528NOYES
CVE-2009-4229HIGH
Multiple SQL injection vulnerabilities in ActiveWebSoftwares Active Bids allow remote attackers to execute arbitrary SQL commands via (1) the catid parameter in the PATH_INFO to th
Dec 8, 20097.528NOYES
CVE-2008-6889HIGH
SQL injection vulnerability in Merchantsadd.asp in ASPReferral 5.3 allows remote attackers to execute arbitrary SQL commands via the AccountID parameter.
Aug 3, 20097.528NOYES
CVE-2008-6873HIGH
SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the TabOpenQuickTab1 parameter to (1) popaccounts.aspx, (2) address
Jul 23, 20097.528NOYES
CVE-2008-6387MEDIUM
Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct
Mar 2, 20095.028NOYES
CVE-2008-6380HIGH
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.
Mar 2, 20097.528NOYES
View all 36 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products36 CVEs
14%
86%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown36 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown36 (100.0%)
User Interaction
None0 (0.0%)
Unknown36 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown36 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (36 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
35 CVEs
97.2% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Activewebsoftwares.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Activewebsoftwares — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Activewebsoftwares's Products

View all 1 CNAs →

Top CWEs