Farsight develops a DNS data collection and analysis platform centered on its Passive DNS server product, which serves security teams and infrastructure operators tracking DNS activity and threat intelligence. The observed vulnerability profile reflects typical web-application exposure, with cross-site scripting weaknesses appearing in the product's query and reporting interfaces. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Farsight over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-23286MEDIUM Cross Site Scripting (XSS) vulnerability in Provide server 14.4 allows attackers to execute arbitrary code through the server-log via username field from the login form. | Feb 10, 2023 | 6.1 | 31 | NO | YES |
CVE-2023-37222MEDIUM
Farsight Tech Nordic AB ProVide version 14.5 - Multiple XSS vulnerabilities (CWE-79) can be exploited by a user with administrator privilege.
| Sep 3, 2023 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Farsight.
Media articles that mention a CVE ID that affects a product developed by Farsight — matched by CVE ID, not by vendor name.