Gsoap
Vendor:
First CVE: Jul 20, 2017 · Active for 9 years
11
Total CVEs
More Total CVEs than 89% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Gsoap over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 20, 2017
9 years ago
Most Recent CVE
Feb 18, 2026
157 days ago
CVE Severity & Scoring
Gsoap11 CVEs
82%
18%
All CVEs352,427 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (81.8%)
High2 (18.2%)
Unknown0 (0.0%)
User Interaction
None11 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None11 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9765HIGH Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2.8.x before 2.8.48, as used on Axis cameras and other devices, allows remote attackers to execute arbitrary co | Jul 20, 2017 | 8.1 | 38 | NO | NO |
CVE-2019-6973HIGH Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server (based on gSOAP 2.8.x) is configured for an iterative queuei | Mar 21, 2019 | 7.5 | 34 | NO | YES |
CVE-2021-21783CRITICAL A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An att | Mar 25, 2021 | 9.8 | 33 | NO | NO |
CVE-2020-13576CRITICAL A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An att | Feb 10, 2021 | 9.8 | 31 | NO | NO |
CVE-2019-25355HIGH gSOAP 2.8 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by manipulating HTTP path traversal techniques. Attackers can re | Feb 18, 2026 | 7.5 | 25 | NO | NO |
CVE-2020-13578HIGH A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attack | Feb 10, 2021 | 7.5 | 25 | NO | NO |
CVE-2019-7659HIGH Genivia gSOAP 2.7.x and 2.8.x before 2.8.75 allows attackers to cause a denial of service (application abort) or possibly have unspecified other impact if a server application is b | Feb 9, 2019 | 8.1 | 25 | NO | NO |
CVE-2020-13575HIGH A denial-of-service vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An atta | Feb 10, 2021 | 7.5 | 24 | NO | NO |
CVE-2020-13574HIGH A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attack | Feb 10, 2021 | 7.5 | 21 | NO | NO |
CVE-2024-4227HIGH In Genivia gSOAP with a specific configuration an unauthenticated remote attacker can generate a high CPU load when forcing to parse an XML having duplicate ID attributes which can | Jan 15, 2025 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Gsoap
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.8.9 | 1 | 8.1 | 21.9% | 0 | 0 |
| 2.8.8 | 1 | 8.1 | 21.9% | 0 | 0 |
| 2.8.7 | 1 | 8.1 | 21.9% | 0 | 0 |
| 2.8.6 | 1 | 8.1 | 21.9% | 0 | 0 |
| 2.8.5 | 1 | 8.1 | 21.9% | 0 | 0 |
| 2.8.47 | 1 | 8.1 | 21.9% | 0 | 0 |
| 2.8.46 | 1 | 8.1 | 21.9% | 0 | 0 |
| 2.8.45 | 1 | 8.1 | 21.9% | 0 | 0 |
| 2.8.44 | 1 | 8.1 | 21.9% | 0 | 0 |
| 2.8.43 | 1 | 8.1 | 21.9% | 0 | 0 |
| 2.8.42 | 1 | 8.1 | 21.9% | 0 | 0 |
| 2.8.41 | 1 | 8.1 | 21.9% | 0 | 0 |
| 2.8.40 | 1 | 8.1 | 21.9% | 0 | 0 |
| 2.8.4 | 1 | 8.1 | 21.9% | 0 | 0 |
| 2.8.39 | 1 | 8.1 | 21.9% | 0 | 0 |
| 2.8.38 | 1 | 8.1 | 21.9% | 0 | 0 |
| 2.8.37 | 1 | 8.1 | 21.9% | 0 | 0 |
| 2.8.36 | 1 | 8.1 | 21.9% | 0 | 0 |
| 2.8.35 | 1 | 8.1 | 21.9% | 0 | 0 |
| 2.8.34 | 1 | 8.1 | 21.9% | 0 | 0 |