Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Articatech

First CVE: Dec 7, 2017Active for: 9 yearsTotal CVEs: 17
69.2
VTI Score
TOP TARGET

Articatech's vulnerability footprint centers on a narrow line of proxy and web-filtering products deployed in network perimeter and content-control roles, where internet-facing exposure and administrative functionality create a high-value target. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, concentrated in weakness classes such as OS command injection, cross-site scripting, authentication bypass, path traversal, and insecure file permissions that are characteristic of web-facing administrative interfaces. Defenders should treat Articatech product instances as patching priorities, particularly internet-reachable deployments; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Articatech over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 7, 2017
8 years ago
Most Recent CVE
Mar 21, 2024
855 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-17506CRITICAL
Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in f
Aug 12, 20209.891NOYES
CVE-2024-2054CRITICAL
The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" us
Mar 21, 20249.887NOYES
CVE-2020-17505HIGH
Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privilege
Aug 12, 20208.882NOYES
CVE-2020-13158HIGH
Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parameter.
Jun 22, 20207.558NOYES
CVE-2024-2053HIGH
The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" us
Mar 21, 20247.555NOYES
CVE-2017-17055CRITICAL
Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involving the username-form-id param
Dec 7, 20179.036NOYES
CVE-2024-2056CRITICAL
Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service is running, running
Mar 5, 20249.834NONO
CVE-2020-13159CRITICAL
Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_mac, Hostname, or Alias field. NOTE: this may overl
Jun 22, 20209.834NONO
CVE-2022-37153MEDIUM
An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.login.php.
Aug 24, 20226.131NOYES
CVE-2021-41739CRITICAL
A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp.
May 5, 20229.830NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
18%
41%
41%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network17 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (76.5%)
Unknown0 (0.0%)
Required4 (23.5%)
Privileges Required
Low3 (17.6%)
High2 (11.8%)
None12 (70.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
17.6% of CVEs· 99th percentile
Nuclei
5 CVEs
29.4% of CVEs· 98th percentile
ExploitDB
3 CVEs
17.6% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Articatech.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Articatech — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Articatech's Products

View all 2 CNAs →

Top CWEs