Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Auvesy

First CVE: Oct 22, 2021Active for: 5 yearsTotal CVEs: 17
52.3
VTI Score
TOP TARGET

Auvesy develops VersionDog, a version-control and release-management platform widely used in industrial and enterprise environments to track configuration and software changes. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through weakness classes including resource-exhaustion flaws, out-of-bounds writes, authentication bypasses, and path-manipulation issues that reflect the product's role in managing access to sensitive software artifacts and system configurations. Defenders should prioritize patching this vendor's disclosures given the elevation in severity and the access-control functions the product performs; live exploitation status and current exposure counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
17.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
8.4
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Auvesy over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 22, 2021
4 years ago
Most Recent CVE
Oct 22, 2021
1,736 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-38459CRITICAL
The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level. If a specific .exe is not restarted often, it is possible to access the
Oct 22, 20219.831NONO
CVE-2021-38477CRITICAL
There are multiple API function codes that permit reading and writing data to or from files and directories, which could lead to the manipulation and/or the deletion of files.
Oct 22, 20219.830NONO
CVE-2021-38457CRITICAL
The server permits communication without any authentication procedure, allowing the attacker to initiate a session with the server without providing any form of authentication.
Oct 22, 20219.830NONO
CVE-2021-38481CRITICAL
The scheduler service running on a specific TCP port enables the user to start and stop jobs. There is no sanitation of the supplied JOB ID provided to the function. An attacker ma
Oct 22, 20219.829NONO
CVE-2021-38471CRITICAL
There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existing files or create new files.
Oct 22, 20219.129NONO
CVE-2021-38449CRITICAL
Some API functions permit by-design writing or copying data into a given buffer. Since the client controls these parameters, an attacker could rewrite the memory in any location of
Oct 22, 20219.829NONO
CVE-2021-38475HIGH
The database connection to the server is performed by calling a specific API, which could allow an unprivileged user to gain SYSDBA permissions.
Oct 22, 20218.827NONO
CVE-2021-38473HIGH
The affected product’s code base doesn’t properly control arguments for specific functions, which could lead to a stack overflow.
Oct 22, 20218.827NONO
CVE-2021-38453CRITICAL
Some API functions allow interaction with the registry, which includes reading values as well as data modification.
Oct 22, 20219.127NONO
CVE-2021-38467HIGH
A specific function code receives a raw pointer supplied by the user and deallocates this pointer. The user can then control what memory regions will be freed and cause use-after-f
Oct 22, 20218.125NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
18%
41%
41%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.9%)
Network16 (94.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (88.2%)
Unknown0 (0.0%)
Required2 (11.8%)
Privileges Required
Low7 (41.2%)
High0 (0.0%)
None10 (58.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Auvesy.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Auvesy — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Auvesy's Products

View all 1 CNAs →

Top CWEs