Ehoney Project maintains a honeypot platform designed to detect and analyze attack activity, a narrowly scoped but strategically important security tool that occupies a unique defensive niche. Vulnerabilities affecting the product skew strongly toward critical severity and recur through weakness classes including improper input neutralization, SQL injection, and privilege assignment flaws—patterns that reflect the product's role in ingesting and processing untrusted attacker-supplied data. Defenders deploying honeypot infrastructure should treat this vendor's advisories as urgent despite the small portfolio; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ehoney Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3735CRITICAL A vulnerability was found in seccome Ehoney. It has been rated as critical. This issue affects some unknown processing of the file /api/public/signup. The manipulation leads to imp | Oct 28, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-3732CRITICAL A vulnerability was found in seccome Ehoney and classified as critical. Affected by this issue is some unknown functionality of the file /api/v1/bait/set. The manipulation of the a | Oct 28, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-3730CRITICAL A vulnerability, which was classified as critical, was found in seccome Ehoney. Affected is an unknown function of the file /api/v1/attack/falco. The manipulation of the argument P | Oct 28, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-3729CRITICAL A vulnerability, which was classified as critical, has been found in seccome Ehoney. This issue affects some unknown processing of the file /api/v1/attack. The manipulation of the | Oct 28, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-3731CRITICAL A vulnerability has been found in seccome Ehoney and classified as critical. Affected by this vulnerability is an unknown functionality of the file /api/v1/attack/token. The manipu | Oct 28, 2022 | 9.8 | 24 | NO | NO |
CVE-2022-38868HIGH SQL Injection vulnerability in Ehoney version 2.0.0 in models/protocol.go and models/images.go, allows attackers to execute arbitrary code. | Feb 15, 2023 | 7.2 | 23 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ehoney Project.
Media articles that mention a CVE ID that affects a product developed by Ehoney Project — matched by CVE ID, not by vendor name.