Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Isode

First CVE: Feb 15, 2006Active for: 20 yearsTotal CVEs: 6

Isode is a messaging and directory systems vendor with a niche portfolio centered on its M-Link mail transfer agent and M-Vault secure messaging and storage products, which serve specialized enterprise communication requirements. The vendor's durable vulnerability signal reflects its position in critical messaging infrastructure: recurring weaknesses in access control, input validation, memory safety, and credential handling recur across its products and indicate the authentication and protocol-parsing demands of secure communication systems. Public exploit tooling has been associated with this vendor's disclosures; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Isode over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 15, 2006
20 years ago
Most Recent CVE
Jan 1, 2023
1,300 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2006-0710HIGH
Double free vulnerability in isode.eddy in Isode M-Vault Server 11.3 allows remote attackers to execute arbitrary code via a crafted LDAP request, as demonstrated by ProtoVer Sampl
Feb 15, 20067.529NOYES
CVE-2022-47634HIGH
M-Link Archive Server in Isode M-Link R16.2v1 through R17.0 before R17.0v24 allows non-administrative users to access and manipulate archive data via certain HTTP endpoints, aka LI
Jan 1, 20238.126NONO
CVE-2022-47581HIGH
Isode M-Vault 16.0v0 through 17.x before 17.0v24 can crash upon an LDAP v1 bind request.
Dec 21, 20227.524NONO
CVE-2022-32389HIGH
Isode SWIFT v4.0.2 was discovered to contain hard-coded credentials in the Registry Editor. This allows attackers to access sensitive information such as user credentials and certi
Jul 14, 20227.524NONO
CVE-2014-2742HIGH
Isode M-Link before 16.0v7 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) v
Apr 11, 20147.820NONO
CVE-2012-4669MEDIUM
M-Link R14.6 before R14.6v14 and R15.1 before R15.1v10 does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domai
Aug 25, 20125.819NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
17%
83%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network3 (50.0%)
Unknown3 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (50.0%)
High0 (0.0%)
Unknown3 (50.0%)
User Interaction
None3 (50.0%)
Unknown3 (50.0%)
Required0 (0.0%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None2 (33.3%)
Unknown3 (50.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
16.7% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Isode.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Isode — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Isode's Products

View all 2 CNAs →

Top CWEs