Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Dogtagpki

First CVE: Jul 3, 2018Active for: 8 yearsTotal CVEs: 16
42.0
VTI Score
High

Dogtagpki maintains a specialized public-key infrastructure and certificate-management toolkit, a narrowly scoped but prominent product in the identity and authentication supply chain. Vulnerabilities affecting the vendor recur around application-layer weaknesses including cross-site scripting, memory management flaws, cleartext storage of sensitive data, and improper access control—exposures that reflect the complexity of credential handling and trust-store management in PKI software. A moderate tendency toward public exploit availability characterizes this vendor's disclosures; defenders should prioritize patching instances that handle production certificates and are exposed to untrusted input. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Dogtagpki over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 3, 2018
8 years ago
Most Recent CVE
Oct 4, 2023
1,024 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-2414HIGH
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbi
Jul 29, 20227.574NOYES
CVE-2018-1080HIGH
Dogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the application of ACL allow and deny rules to be reversed. If
Jul 3, 20188.127NONO
CVE-2021-20179HIGH
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is no
Mar 15, 20218.126NONO
CVE-2021-3551HIGH
A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to
Feb 16, 20227.825NONO
CVE-2021-4213HIGH
A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an
Aug 24, 20227.524NONO
CVE-2017-7537HIGH
It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4. An attacker could potentially
Jul 26, 20187.524NONO
CVE-2020-15720MEDIUM
In Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did not enable python-requests certificate validation. Since the verify parameter was hard-coded in all request fun
Jul 14, 20206.823NONO
CVE-2019-10221MEDIUM
A Reflected Cross Site Scripting vulnerability was found in all pki-core 10.x.x versions, where the pki-ca module from the pki-core server. This flaw is caused by missing sanitizat
Mar 20, 20206.122NONO
CVE-2019-10179MEDIUM
A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery request search page, enabling a R
Mar 20, 20206.122NONO
CVE-2019-10178MEDIUM
It was found that the Token Processing Service (TPS) did not properly sanitize the Token IDs from the "Activity" page, enabling a Stored Cross Site Scripting (XSS) vulnerability. A
Mar 18, 20206.122NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
63%
38%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (6.3%)
Network15 (93.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (75.0%)
High4 (25.0%)
Unknown0 (0.0%)
User Interaction
None7 (43.8%)
Unknown0 (0.0%)
Required9 (56.3%)
Privileges Required
Low3 (18.8%)
High1 (6.3%)
None12 (75.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
6.2% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Dogtagpki.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Dogtagpki — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Dogtagpki's Products

View all 2 CNAs →

Top CWEs