Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Genivia

First CVE: Jul 20, 2017Active for: 9 yearsTotal CVEs: 11
63.1
VTI Score
TOP TARGET

Genivia maintains gSOAP, a widely embedded code-generation toolkit for SOAP/XML web services that, despite a narrow product scope, appears in many downstream applications and embedded systems. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit availability; the recurring weakness classes, including NULL-pointer dereferences, integer overflows and their buffer-overflow consequences, and path-traversal flaws, reflect the low-level parsing and string-handling demands of code-generated C/C++ stubs. Defenders should inventory products that use gSOAP-generated stubs rather than treating the toolkit alone as the exposure boundary, since remediation typically requires regeneration and recompilation downstream; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
2.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Genivia over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 20, 2017
9 years ago
Most Recent CVE
Feb 18, 2026
156 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-9765HIGH
Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2.8.x before 2.8.48, as used on Axis cameras and other devices, allows remote attackers to execute arbitrary co
Jul 20, 20178.138NONO
CVE-2019-6973HIGH
Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server (based on gSOAP 2.8.x) is configured for an iterative queuei
Mar 21, 20197.534NOYES
CVE-2021-21783CRITICAL
A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An att
Mar 25, 20219.833NONO
CVE-2020-13576CRITICAL
A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An att
Feb 10, 20219.831NONO
CVE-2019-25355HIGH
gSOAP 2.8 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by manipulating HTTP path traversal techniques. Attackers can re
Feb 18, 20267.525NONO
CVE-2020-13578HIGH
A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attack
Feb 10, 20217.525NONO
CVE-2019-7659HIGH
Genivia gSOAP 2.7.x and 2.8.x before 2.8.75 allows attackers to cause a denial of service (application abort) or possibly have unspecified other impact if a server application is b
Feb 9, 20198.125NONO
CVE-2020-13575HIGH
A denial-of-service vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An atta
Feb 10, 20217.524NONO
CVE-2020-13574HIGH
A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attack
Feb 10, 20217.521NONO
CVE-2024-4227HIGH
In Genivia gSOAP with a specific configuration an unauthenticated remote attacker can generate a high CPU load when forcing to parse an XML having duplicate ID attributes which can
Jan 15, 20257.520NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
82%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (81.8%)
High2 (18.2%)
Unknown0 (0.0%)
User Interaction
None11 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None11 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Genivia.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Genivia — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Genivia's Products

View all 4 CNAs →

Top CWEs