Hummingbird's vulnerability profile centers on a focused portfolio of enterprise collaboration and document-management products, including offerings such as Connectivity, Cyberdocs, Exceed, and Enterprise Collaboration platforms, which serve as critical infrastructure for business communication and content sharing. The vendor's disclosures recur around memory-safety and bounds-checking weaknesses, and public exploit code has frequently become available for vulnerabilities affecting this portfolio. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hummingbird over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-1815MEDIUM Multiple buffer overflows in Hummingbird Connectivity inetD 10.0.0.1 and 9.0.0.4 allows attackers to cause a denial of service and possibly execute arbitrary code via (1) an FTP co | Jun 1, 2005 | 5.0 | 55 | NO | YES |
CVE-2008-4728HIGH Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in Hummingbird Deployment Wizard 2008 allow remote attackers t | Oct 24, 2008 | 9.3 | 50 | NO | YES |
CVE-2008-4729MEDIUM Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Control 13.0 and earlier allows remote attackers to execute arbi | Oct 24, 2008 | 6.8 | 29 | NO | YES |
CVE-2024-43117HIGH Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a throug | Aug 26, 2024 | 8.8 | 24 | NO | NO |
CVE-2003-1103HIGH SQL injection vulnerability in loginact.asp for Hummingbird CyberDOCS before 3.9 allows remote attackers to execute arbitrary SQL commands. | Dec 31, 2003 | 7.5 | 24 | NO | NO |
CVE-2024-43118HIGH Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a through <= 3.9.1. | Nov 1, 2024 | 8.8 | 23 | NO | NO |
CVE-2006-0173MEDIUM Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to misrepresent the type and name of a file via modified doc_ext and i | Jan 11, 2006 | 4.0 | 21 | NO | YES |
CVE-2006-0174MEDIUM Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intranet IP addresses and enumeration | Jan 11, 2006 | 4.0 | 21 | NO | YES |
CVE-2005-2599HIGH Hummingbird FTP for Connectivity 10.0 uses weak encryption (trivial encoding) to store the user's password in the FTP profile, which allows attackers to gain privileges. | Aug 17, 2005 | 7.5 | 19 | NO | NO |
CVE-1999-1280HIGH Hummingbird Exceed 6.0.1.0 inadvertently includes a DLL that was meant for development and testing, which logs user names and passwords in cleartext in the test.log file. | Dec 3, 1998 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hummingbird.
Media articles that mention a CVE ID that affects a product developed by Hummingbird — matched by CVE ID, not by vendor name.