Nifi

Vendor:

First CVE: Jun 12, 2017 · Active for 9 years

50
Total CVEs
More Total CVEs than 98% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Nifi over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 12, 2017
9 years ago
Most Recent CVE
Jun 22, 2026
32 days ago

CVE Severity & Scoring

Nifi50 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local2 (4.0%)
Network48 (96.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low47 (94.0%)
High3 (6.0%)
Unknown0 (0.0%)
User Interaction
None39 (78.0%)
Unknown0 (0.0%)
Required11 (22.0%)
Privileges Required
Low20 (40.0%)
High4 (8.0%)
None26 (52.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (50 CVEs).

50 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL wit
Jun 12, 20238.874NOYES
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality
Feb 26, 20215.361NONO
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property
Aug 20, 20197.339NONO
Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricte
Jun 22, 20267.234NONO
The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi 2.0.0-M1 through 2.8.0. The Ti
May 8, 20268.834NONO
Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming.
Jun 22, 20267.232NONO
A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause remote code execution. The fix to properly handle these head
Jan 23, 20189.832NONO
Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration proper
Jun 22, 20266.330NONO
Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers, when cr
Dec 28, 20245.430NOYES
Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or remote code execution. The fix to disable external general
May 23, 20189.830NONO

Exploit Exposure

Signals from CVEs in this product scope (50 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.0% of CVEs· 96th percentile
Nuclei
1 CVE
2.0% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (50 CVEs).

Media Mentions

Signals from CVEs in this product scope (50 CVEs).

Top CNAs Publishing CVEs For Nifi

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.7.018.80.4%00
2.0.035.110.6%00
1.3.016.51.9%00
1.2.036.72.3%00
1.15.017.329.8%00
1.14.017.329.8%00
1.13.015.378.0%00
1.1.236.72.3%00
1.1.157.52.8%00
1.10.015.34.0%00
1.1.067.12.6%00
1.0.136.72.3%00
1.0.036.72.3%00
0.7.128.73.4%00
0.7.028.73.4%00