Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gwos

First CVE: May 8, 2013Active for: 13 yearsTotal CVEs: 15
36.1
VTI Score
Medium

Gwos develops GroundWork Monitor, a network and infrastructure monitoring platform that occupies a prominent role in enterprise observability and IT operations environments. The vendor's vulnerability profile centers on application-layer weaknesses endemic to web-facing monitoring interfaces: improper input validation, CSRF flaws, code injection, path traversal, and exposure of sensitive configuration data recur across its disclosures and reflect the attack surface presented by privileged, internet-accessible management tools. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
15.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 28% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Gwos over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 8, 2013
13 years ago
Most Recent CVE
May 8, 2013
4,825 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-3502MEDIUM
monarch_scan.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands, and consequently obtain sensitive
May 8, 20136.563NOYES
CVE-2013-3512MEDIUM
The Cacti component in GroundWork Monitor Enterprise 6.7.0 does not properly perform authorization checks, which allows remote authenticated users to read or modify configuration s
May 8, 20136.522NONO
CVE-2013-3513MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in the Noma component in GroundWork Monitor Enterprise 6.7.0 allow remote attackers to hijack the authentication of unspe
May 8, 20136.821NONO
CVE-2013-3499HIGH
GroundWork Monitor Enterprise 6.7.0 performs authentication on the basis of the HTTP Referer header, which allows remote attackers to obtain administrative privileges or access fil
May 8, 20137.521NONO
CVE-2013-3508MEDIUM
html/System-Files.php in the System File Overview feature in the NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary comman
May 8, 20136.520NONO
CVE-2013-3506HIGH
cgi-bin/performance/perfchart.cgi in the Performance component in GroundWork Monitor Enterprise 6.7.0 does not properly restrict XML content, which allows remote attackers to execu
May 8, 20137.520NONO
CVE-2013-3500HIGH
The Foundation webapp admin interface in GroundWork Monitor Enterprise 6.7.0 uses the nagios account as the owner of writable files under /usr/local/groundwork, which allows contex
May 8, 20137.520NONO
CVE-2013-3504MEDIUM
Directory traversal vulnerability in monarch.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to overwrite arbitrary files by l
May 8, 20135.519NONO
CVE-2013-3510MEDIUM
Multiple SQL injection vulnerabilities in GroundWork Monitor Enterprise 6.7.0 allow remote authenticated users to execute arbitrary SQL commands via (1) nedi/html/System-Export.php
May 8, 20136.518NONO
CVE-2013-3509MEDIUM
html/System-NeDi.php in the NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the sc
May 8, 20136.518NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
73%
20%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown15 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown15 (100.0%)
User Interaction
None0 (0.0%)
Unknown15 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown15 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
6.7% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
6.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gwos.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gwos — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gwos's Products

View all 1 CNAs →

Top CWEs