Cert's vulnerability profile centers on its Vince vulnerability information and coordination platform, which faces the security challenges inherent to web-based coordination and data-exchange tools. The recurring weakness classes—including untrusted deserialization, cross-site scripting, injection flaws, default permissions misconfigurations, and open redirects—reflect the input-handling, authentication, and trust-boundary demands of a system that aggregates and distributes sensitive vulnerability intelligence. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cert over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40238HIGH A Remote Code Injection vulnerability exists in CERT software prior to version 1.50.5. An authenticated attacker can inject arbitrary pickle object as part of a user's profile. Thi | Oct 26, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-40257MEDIUM An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via a crafted email with HTML content in the S | Oct 10, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-40248MEDIUM An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via form using the "Product Affected" field. | Oct 10, 2022 | 5.4 | 20 | NO | NO |
CVE-2024-10469MEDIUM VINCE versions before 3.0.9 is vulnerable to exposure of User information to authenticated users. | Oct 28, 2024 | 6.5 | 19 | NO | NO |
CVE-2022-25799MEDIUM An open redirect vulnerability exists in CERT/CC VINCE software prior to 1.50.0. An attacker could send a link that has a specially crafted URL and convince the user to click the l | Aug 16, 2022 | 6.1 | 17 | NO | NO |
CVE-2024-9953MEDIUM A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticated administrative user can inject an arbitrary pickle object | Oct 14, 2024 | 4.9 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cert.
Media articles that mention a CVE ID that affects a product developed by Cert — matched by CVE ID, not by vendor name.