Darktrace develops enterprise security products, including its Enterprise Immune System and Threat Visualizer platforms, which operate as network monitoring and anomaly-detection appliances deployed across corporate infrastructure. The observed vulnerability exposure centers on web-application input and authorization handling, with recurrent weakness classes including cross-site request forgery, cross-site scripting, improper authorization checks, and open redirects that are typical of browser-facing security consoles. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Darktrace over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-22854MEDIUM DOM-based HTML injection vulnerability in the main page of Darktrace Threat Visualizer version 6.1.27 (bundle version 61050) and before has been identified. A URL, crafted by a rem | Feb 16, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-29656MEDIUM An improper authorization vulnerability in Darktrace mobile app (Android) prior to version 6.0.15 allows disabled and low-privilege users to control "antigena" actions(block/unbloc | Jul 6, 2023 | 6.1 | 18 | NO | NO |
CVE-2019-9596MEDIUM Darktrace Enterprise Immune System before 3.1 allows CSRF via the /whitelisteddomains endpoint. | Oct 23, 2019 | 6.5 | 18 | NO | NO |
CVE-2019-9597MEDIUM Darktrace Enterprise Immune System before 3.1 allows CSRF via the /config endpoint. | Oct 23, 2019 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Darktrace.
Media articles that mention a CVE ID that affects a product developed by Darktrace — matched by CVE ID, not by vendor name.