Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Caucho

First CVE: Nov 23, 2004Active for: 22 yearsTotal CVEs: 11
40.4
VTI Score
High

Caucho's vulnerability profile centers on Resin, a Java application server and web container that sits in the request-handling path of many deployments. The recurring weakness classes—cross-site scripting, input validation flaws, and path traversal—reflect the parsing and access-control demands of a web application platform, and vulnerabilities affecting this vendor have a tendency to acquire public exploit tooling. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Caucho over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 23, 2004
21 years ago
Most Recent CVE
Apr 4, 2022
1,572 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-44138HIGH
There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ;
Apr 4, 20227.542NOYES
CVE-2004-0281MEDIUM
Caucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-INF/ directory via an HTTP request for "WEB-INF..", which is
Nov 23, 20045.026NOYES
CVE-2010-2032MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possibly other versions allow remote
May 24, 20104.325NOYES
CVE-2012-2967HIGH
Caucho Quercus, as distributed in Resin before 4.0.29, does not properly implement the == (equals sign equals sign) operator for comparisons, which has unspecified impact and conte
Aug 12, 20127.523NONO
CVE-2012-2969MEDIUM
Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to bypass intended restrictions on filename extensions for created files via a %00 sequence in a path
Aug 12, 20126.422NONO
CVE-2012-2966HIGH
Caucho Quercus, as distributed in Resin before 4.0.29, overwrites entries in the SERVER superglobal array on the basis of POST parameters, which has unspecified impact and remote a
Aug 12, 20127.522NONO
CVE-2012-2965HIGH
Caucho Quercus, as distributed in Resin before 4.0.29, does not properly handle unspecified characters in the names of variables, which has unknown impact and remote attack vectors
Aug 12, 20127.522NONO
CVE-2012-2968MEDIUM
Directory traversal vulnerability in Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to create files in arbitrary directories via a .. (dot dot) in a
Aug 12, 20125.019NONO
CVE-2010-2087MEDIUM
Oracle Mojarra 1.2_14 and 2.0.2, as used in IBM WebSphere Application Server, Caucho Resin, and other applications, does not properly handle an unencrypted view state, which allows
May 27, 20104.316NONO
CVE-2014-2966MEDIUM
The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended text restrictions via crafted
Jul 26, 20145.015NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
64%
36%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (9.1%)
Unknown10 (90.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (9.1%)
High0 (0.0%)
Unknown10 (90.9%)
User Interaction
None1 (9.1%)
Unknown10 (90.9%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (9.1%)
Unknown10 (90.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
9.1% of CVEs· 96th percentile
ExploitDB
2 CVEs
18.2% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Caucho.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Caucho — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Caucho's Products

View all 2 CNAs →

Top CWEs