Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hawt

First CVE: Aug 17, 2017Active for: 9 yearsTotal CVEs: 8

Hawt develops Hawtio, a web-based management console for monitoring and administering Java applications and middleware, with its vulnerability profile skewing strongly toward critical-severity outcomes across a narrowly scoped product line. The recurring weakness classes center on web-application-layer flaws including cross-site request forgery, path traversal, improper authentication and authorization, and sensitive information exposure in error messages—attack vectors characteristic of internet-exposed management interfaces. Defenders should treat Hawt advisories as high-priority for any exposed or internally accessible instances; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
8.4
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Hawt over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 17, 2017
8 years ago
Most Recent CVE
Jun 1, 2023
1,149 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-9827CRITICAL
Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substrin
Jul 3, 20199.837NONO
CVE-2014-0121CRITICAL
The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.
Dec 29, 20179.831NONO
CVE-2017-2589CRITICAL
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed betw
Jul 26, 20189.028NONO
CVE-2017-2617HIGH
hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a t
May 22, 20187.826NONO
CVE-2017-7556HIGH
Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote attackers to trick the user to visit their website containing a malicious script whic
Aug 17, 20178.826NONO
CVE-2014-0120HIGH
Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run comma
Dec 29, 20178.823NONO
CVE-2017-2594HIGH
hawtio before versions 2.0-beta-1, 2.0-beta-2 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 is vulnerable to a path traversal that leads to a NullPointerException with a full stacktrace. An atta
May 8, 20187.521NONO
CVE-2023-33544MEDIUM
hawtio 2.17.2 is vulnerable to Path Traversal. it is possible to input malicious zip files, which can result in the high-risk files after decompression being stored in any location
Jun 1, 20235.516NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
13%
50%
38%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (25.0%)
Network6 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (37.5%)
Unknown0 (0.0%)
Required5 (62.5%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None7 (87.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hawt.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hawt — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hawt's Products

View all 2 CNAs →

Top CWEs