Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Broadcom

First CVE: Nov 12, 1998Active for: 28 yearsTotal CVEs: 653
64.6
VTI Score
TOP TARGET

Broadcom's vulnerability footprint spans a large and diverse portfolio of storage networking, fabric infrastructure, and backup software solutions that serve enterprise data centers and mission-critical environments, representing a substantial and widely deployed attack surface. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency toward public exploit code availability, creating material risk for exposed deployments. The exposure recurs across flagship products including Fabric Operating System, SAN management software, and BackupEdge components, with recurring weaknesses centered on input validation, memory-safety issues, and web-application flaws such as cross-site scripting that are characteristic of complex enterprise infrastructure. Defenders should prioritize patching for fabric switches and backup appliances exposed to untrusted networks, as these products occupy high-value positions in backup and replication workflows. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
653
Total CVEs
More Total CVEs than 100% of tracked vendors
0.1
Avg CVEs / Product / Year
Bottom 1%
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.6%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Broadcom over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 12, 1998
27 years ago
Most Recent CVE
Jul 10, 2026
18 days ago

Products(227 total)

Top CVEs

Signals from CVEs in this vendor scope (653 CVEs).

653 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-0160HIGH
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive inform
Apr 7, 20147.599YESYES
CVE-2021-40438CRITICAL
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Sep 16, 20219.097YESYES
CVE-2018-1273CRITICAL
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of s
Apr 11, 20189.897YESYES
CVE-2010-0425HIGH
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure
Mar 5, 201010.091NOYES
CVE-2011-1653HIGH
Multiple SQL injection vulnerabilities in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 allow remote attackers to execute arbitrary SQL commands
Apr 18, 201110.090NOYES
CVE-2020-8012CRITICAL
CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller) component. A remote attacker
Feb 18, 20209.886NOYES
CVE-2008-4397HIGH
Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to exec
Oct 14, 200810.084NOYES
CVE-2005-2668HIGH
Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allow remote attackers to execute arb
Aug 23, 200510.084NOYES
CVE-2007-2139HIGH
Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used in BrightStor ARCserve Backup 9.01 throu
Apr 25, 200710.083NOYES
CVE-2007-0449HIGH
Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1 SP1, Mobile Backup r4.0, Desktop and Business Protection Sui
Jan 23, 200710.083NOYES
View all 653 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products653 CVEs
37%
48%
13%
Severity distribution among all CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local131 (20.1%)
Network325 (49.8%)
Unknown173 (26.5%)
Physical2 (0.3%)
Adjacent Network15 (2.3%)
Attack Complexity
Low449 (68.8%)
High31 (4.7%)
Unknown173 (26.5%)
User Interaction
None388 (59.4%)
Unknown173 (26.5%)
Required91 (13.9%)
Privileges Required
Low144 (22.1%)
High45 (6.9%)
None291 (44.6%)
Unknown173 (26.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (653 CVEs).

CISA KEV
4 CVEs
0.6% of CVEs· 99th percentile
Metasploit
22 CVEs
3.4% of CVEs· 98th percentile
Nuclei
3 CVEs
0.5% of CVEs· 95th percentile
ExploitDB
66 CVEs
10.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Broadcom.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Broadcom — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Broadcom's Products

View all 19 CNAs →

Top CWEs