Jmeter
Vendor:
First CVE: Feb 13, 2018 · Active for 8 years
14
Total CVEs
More Total CVEs than 91% of tracked products
4.7
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
9.1
Avg CVSS
Higher Avg CVSS than 85% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Jmeter over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 13, 2018
8 years ago
Most Recent CVE
Mar 23, 2021
1,949 days ago
CVE Severity & Scoring
Jmeter14 CVEs
29%
71%
All CVEs352,231 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (7.1%)
High1 (7.1%)
None12 (85.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21351CRITICAL XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arb | Mar 23, 2021 | 9.1 | 82 | NO | YES |
CVE-2021-21345CRITICAL XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficien | Mar 23, 2021 | 9.9 | 80 | NO | YES |
CVE-2021-21346CRITICAL XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execu | Mar 23, 2021 | 9.8 | 74 | NO | NO |
CVE-2021-21344CRITICAL XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execu | Mar 23, 2021 | 9.8 | 73 | NO | NO |
CVE-2021-21341HIGH XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CP | Mar 23, 2021 | 7.5 | 68 | NO | NO |
CVE-2021-21342CRITICAL XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time co | Mar 23, 2021 | 9.1 | 55 | NO | NO |
CVE-2021-21349HIGH XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data f | Mar 23, 2021 | 8.6 | 53 | NO | NO |
CVE-2021-21343HIGH XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time co | Mar 23, 2021 | 7.5 | 50 | NO | NO |
CVE-2021-21350CRITICAL XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitr | Mar 23, 2021 | 9.8 | 38 | NO | NO |
CVE-2021-21347CRITICAL XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execu | Mar 23, 2021 | 9.8 | 37 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
14.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Jmeter
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.0 | 1 | 9.8 | 2.7% | 0 | 0 |
| 4.0 | 1 | 9.8 | 2.7% | 0 | 0 |
| 3.3 | 2 | 9.8 | 6.8% | 0 | 0 |
| 3.2 | 2 | 9.8 | 6.8% | 0 | 0 |
| 3.1 | 2 | 9.8 | 6.8% | 0 | 0 |
| 3.0 | 2 | 9.8 | 6.8% | 0 | 0 |
| 2.9 | 2 | 9.8 | 6.8% | 0 | 0 |
| 2.8 | 2 | 9.8 | 6.8% | 0 | 0 |
| 2.7 | 2 | 9.8 | 6.8% | 0 | 0 |
| 2.6 | 2 | 9.8 | 6.8% | 0 | 0 |
| 2.5.1 | 2 | 9.8 | 6.8% | 0 | 0 |
| 2.5 | 2 | 9.8 | 6.8% | 0 | 0 |
| 2.4 | 2 | 9.8 | 6.8% | 0 | 0 |
| 2.3.4 | 2 | 9.8 | 6.8% | 0 | 0 |
| 2.3.3 | 2 | 9.8 | 6.8% | 0 | 0 |
| 2.3.2 | 2 | 9.8 | 6.8% | 0 | 0 |
| 2.3.1 | 2 | 9.8 | 6.8% | 0 | 0 |
| 2.3 | 2 | 9.8 | 6.8% | 0 | 0 |
| 2.2 | 2 | 9.8 | 6.8% | 0 | 0 |
| 2.13 | 2 | 9.8 | 6.8% | 0 | 0 |