Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Codeworx Technologies

First CVE: May 31, 2002Active for: 24 yearsTotal CVEs: 12
38.9
VTI Score
Medium

Codeworx Technologies maintains a focused product line centered on the DCP Portal, a web-facing administrative and management platform that has attracted a meaningful volume of public exploit tooling despite a modest CVE footprint. The recurring weakness pattern points to SQL injection and related input-neutralization flaws, reflecting the application-layer validation demands of portal-based credential and configuration management surfaces. Defenders should prioritize patches for this vendor given the public exploit availability and the platform's typical deployment in trusted network segments; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
5.4
Avg CVSS Score
Higher Avg CVSS Score than 22% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Codeworx Technologies over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 31, 2002
24 years ago
Most Recent CVE
Sep 15, 2006
7,252 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2004-2511MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the year, (2) month, and (
Dec 31, 20044.328NOYES
CVE-2006-4836MEDIUM
SQL injection vulnerability in login.php in DCP-Portal SE 6.0 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: The lostpassword.php and
Sep 15, 20065.123NOYES
CVE-2006-4838MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) root_url and (2) dcp_version para
Sep 15, 20064.322NOYES
CVE-2004-2512MEDIUM
CRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and earlier allows remote attackers to conduct HTTP response splitting attacks to spoof web content and poison web
Dec 31, 20044.322NOYES
CVE-2006-4837HIGH
Multiple PHP remote file inclusion vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) library/lib.php
Sep 15, 20067.520NONO
CVE-2005-4227HIGH
Multiple "potential" SQL injection vulnerabilities in DCP-Portal 6.1.1 might allow remote attackers to execute arbitrary SQL commands via (1) the password and username parameters i
Dec 14, 20057.520NONO
CVE-2005-3365HIGH
Multiple SQL injection vulnerabilities in DCP-Portal 6 and earlier allow remote attackers to execute arbitrary SQL commands, possibly requiring encoded characters, via (1) the name
Oct 30, 20057.520NONO
CVE-2005-0454HIGH
Multiple SQL injection vulnerabilities in DCP-Portal 6.1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the lcat, doc, or uid parameters to index.ph
May 2, 20057.519NONO
CVE-2002-0282MEDIUM
DCP-Portal 3.7 through 4.5 allows remote attackers to obtain the physical path of the server via (1) a direct request to add_user.php, or via an invalid new_language parameter in (
May 31, 20025.019NONO
CVE-2006-1120LOW
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 6.1.1 and earlier, with register_globals enabled, allow remote attackers to inject arbitrary web script or HTML vi
Mar 9, 20062.618NOYES
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
8%
58%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown12 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown12 (100.0%)
User Interaction
None0 (0.0%)
Unknown12 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown12 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
41.7% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Codeworx Technologies.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Codeworx Technologies — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Codeworx Technologies's Products

View all 1 CNAs →

Top CWEs