Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cerberus

First CVE: Dec 31, 2003Active for: 23 yearsTotal CVEs: 14
29.3
VTI Score
Low

Cerberus maintains a narrow product line centered on helpdesk and FTP server software that, despite modest portfolio breadth, occupies a moderately prominent position in the vulnerability landscape. Its disclosures cluster around authentication weaknesses, input-handling flaws including cross-site scripting, and memory-safety issues, with a notable tendency toward public exploit availability. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cerberus over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2003
22 years ago
Most Recent CVE
Apr 27, 2026
88 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-6880CRITICAL
Buffer overflow in Cerberus FTP Server 8.0.10.3 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long MLST comman
Mar 17, 20179.841NOYES
CVE-2026-6265HIGH
Insecure preserved inherited permissions vulnerability in Cerberus FTP Server on Windows allows Privilege Escalation.This issue has been resolved in Cerberus FTP Server: 2026.1
Apr 27, 20268.832NONO
CVE-2005-4427HIGH
Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to attachment_send.php, (2) the $
Dec 20, 20057.529NOYES
CVE-2006-6366MEDIUM
Cross-site scripting (XSS) vulnerability in includes/elements/spellcheck/spellwin.php in Cerberus Helpdesk 0.97.3, 2.0 through 2.7, 3.2.1, and 3.3 allows remote attackers to inject
Dec 7, 20066.826NOYES
CVE-2006-5428MEDIUM
rpc.php in Cerberus Helpdesk 3.2.1 does not verify a client's privileges for a display_get_requesters operation, which allows remote attackers to bypass the GUI login and obtain se
Oct 20, 20065.023NOYES
CVE-2006-0509MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote attackers to inject arbitrary web script or HTML via (1) the con
Feb 1, 20064.321NOYES
CVE-2006-4539HIGH
(1) includes/widgets/module_company_tickets.php and (2) includes/widgets/module_track_tickets.php Client Support Center in Cerberus Helpdesk 3.2 Build 317, and possibly earlier, al
Sep 5, 20067.520NONO
CVE-2008-6440MEDIUM
Cerberus Helpdesk before 4.0 (Build 600) allows remote attackers to obtain sensitive information via direct requests for "controllers ... that aren't standard helpdesk pages," poss
Mar 6, 20095.015NONO
CVE-2005-3502MEDIUM
attachment_send.php in Cerberus Helpdesk allows remote attackers to view attachments and tickets of other users via a modified file_id parameter.
Nov 5, 20055.015NONO
CVE-2005-1963MEDIUM
Cerberus Helpdesk 0.97.3 allows remote attackers to obtain sensitive information via certain requests to (1) reports.php, (2) knowledgebase.php, or (3) configuration.php, which lea
Jun 16, 20055.015NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
64%
21%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network2 (14.3%)
Unknown12 (85.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (14.3%)
High0 (0.0%)
Unknown12 (85.7%)
User Interaction
None2 (14.3%)
Unknown12 (85.7%)
Required0 (0.0%)
Privileges Required
Low1 (7.1%)
High0 (0.0%)
None1 (7.1%)
Unknown12 (85.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
35.7% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cerberus.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cerberus — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cerberus's Products

View all 2 CNAs →

Top CWEs