Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Helpsystems

First CVE: Feb 8, 2019Active for: 7 yearsTotal CVEs: 7

Helpsystems develops a focused portfolio of security and administrative tools including the widely used Cobalt Strike adversary-simulation platform, managed file-transfer solutions, and data-classification products that sit in critical operational and security functions. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have a strong, recurring history of confirmed in-the-wild exploitation, reflecting the high-value targets that rely on these tools and the urgency defenders place on patching them. The exposure recurs through weakness classes including resource-exhaustion flaws, authentication bypasses, path traversal, output-encoding defects, and cross-site scripting, which span both the native code and web-facing surfaces of this product family. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 71% of tracked vendors
28.6%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Helpsystems over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 8, 2019
7 years ago
Most Recent CVE
Mar 24, 2023
1,218 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-39197MEDIUM
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To ex
Sep 22, 20226.181YESNO
CVE-2022-42948CRITICAL
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the C
Mar 24, 20239.870YESNO
CVE-2018-20764CRITICAL
A buffer overflow exists in HelpSystems tcpcrypt on Linux, used for BoKS encrypted telnet through BoKS version 6.7.1. Since tcpcrypt is setuid, exploitation leads to privilege esca
Feb 8, 20199.831NONO
CVE-2021-36798HIGH
A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allows remote attackers to crash the C2 server thread and block b
Aug 9, 20217.527NONO
CVE-2022-23317HIGH
CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain relevant information by specifying the URL.
Feb 15, 20227.524NONO
CVE-2021-46830MEDIUM
A path traversal vulnerability exists within GoAnywhere MFT before 6.8.3 that utilize self-registration for the GoAnywhere Web Client. This vulnerability could potentially allow an
Jul 27, 20226.522NONO
CVE-2021-43708MEDIUM
The Labeling tool in Titus Classification Suite 18.8.1910.140 allows users to avoid the generation of a classification label by using Excel's safe mode.
Apr 21, 20225.520NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
43%
29%
29%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (14.3%)
Network6 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (85.7%)
Unknown0 (0.0%)
Required1 (14.3%)
Privileges Required
Low2 (28.6%)
High0 (0.0%)
None5 (71.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
2 CVEs
28.6% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Helpsystems.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Helpsystems — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Helpsystems's Products

View all 1 CNAs →

Top CWEs