Darwin's vulnerability footprint concentrates in a narrowly scoped set of web-facing products, Factor and Darwin itself, where the recurring exposure centers on application-layer input handling and session management. The vulnerabilities affecting this vendor skew toward serious outcomes, with a meaningful share reaching critical severity, reflecting the intersection of web-application complexity and the sensitivity of session and authentication controls in these products. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Darwin over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25985CRITICAL In Factor (App Framework & Headless CMS) v1.0.4 to v1.8.30, improperly invalidate a user’s session even after the user logs out of the application. In addition, user sessions are s | Nov 16, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-25984MEDIUM In Factor (App Framework & Headless CMS) forum plugin, versions v1.3.3 to v1.8.30, are vulnerable to stored Cross-Site Scripting (XSS) at the “post reply” section. An unauthenticat | Nov 16, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-25983MEDIUM In Factor (App Framework & Headless CMS) forum plugin, versions v1.3.8 to v1.8.30, are vulnerable to reflected Cross-Site Scripting (XSS) at the “tags” and “category” parameters in | Nov 16, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-25982MEDIUM In Factor (App Framework & Headless CMS) forum plugin, versions 1.3.5 to 1.8.30, are vulnerable to reflected Cross-Site Scripting (XSS) at the “search” parameter in the URL. An una | Nov 16, 2021 | 6.1 | 20 | NO | NO |
CVE-2008-1146MEDIUM A certain pseudo-random number generator (PRNG) algorithm that uses XOR and 3-bit random hops (aka "Algorithm X3"), as used in OpenBSD 2.8 through 4.2, allows remote attackers to g | Mar 4, 2008 | 6.8 | 18 | NO | NO |
CVE-2008-1147MEDIUM A certain pseudo-random number generator (PRNG) algorithm that uses XOR and 2-bit random hops (aka "Algorithm X2"), as used in OpenBSD 2.6 through 3.4, Mac OS X 10 through 10.5.1, | Mar 4, 2008 | 6.8 | 18 | NO | NO |
CVE-2008-1148MEDIUM A certain pseudo-random number generator (PRNG) algorithm that uses ADD with 0 random hops (aka "Algorithm A0"), as used in OpenBSD 3.5 through 4.2 and NetBSD 1.6.2 through 4.0, al | Mar 4, 2008 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Darwin.
Media articles that mention a CVE ID that affects a product developed by Darwin — matched by CVE ID, not by vendor name.