Acunetix develops a web vulnerability scanner, a specialized security assessment tool with a focused product footprint. Its reported disclosures center on buffer-boundary issues and input-validation weaknesses characteristic of parser and input-handling components in web-scanning engines, though live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Acunetix over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-2994HIGH Stack-based buffer overflow in Acunetix Web Vulnerability Scanner (WVS) 8 build 20120704 allows remote attackers to execute arbitrary code via an HTML file containing an IMG elemen | Apr 27, 2014 | 10.0 | 57 | NO | YES |
CVE-2015-4027HIGH The AcuWVSSchedulerv10 service in Acunetix Web Vulnerability Scanner (WVS) before 10 build 20151125 allows local users to gain privileges via a command parameter in the reporttempl | Dec 17, 2015 | 7.2 | 35 | NO | YES |
CVE-2017-11673CRITICAL Reporter.exe in Acunetix 8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed PRE file, related to a "User Mode Writ | Jul 27, 2017 | 9.8 | 28 | NO | NO |
CVE-2017-11674MEDIUM Reporter.exe in Acunetix 8 allows remote attackers to cause a denial of service (application crash) via a malformed PRE file, related to a "Read Access Violation starting at report | Jul 27, 2017 | 5.5 | 19 | NO | NO |
Acunetix Web Vulnerability Scanner (WVS) 4.0 Build 20060717 and earlier allows remote attackers to cause a denial of service (application crash) via multiple HTTP requests containi | Jan 9, 2007 | 1.9 | 17 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Acunetix.
Media articles that mention a CVE ID that affects a product developed by Acunetix — matched by CVE ID, not by vendor name.