Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

JFrog

First CVE: Dec 9, 2016Active for: 10 yearsTotal CVEs: 35
46.5
VTI Score
High

JFrog develops a focused but widely deployed software artifact repository and release automation platform, Artifactory, that serves as a critical supply-chain node in many enterprise build and deployment pipelines. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and a moderate tendency toward public exploit availability reflecting the platform's high-value and internet-exposed operational role. The exposure recurs through weakness classes including improper access control, cross-site request forgery, and input-validation flaws that are characteristic of web-based repository and integration platforms where authentication, session management, and data-handling logic are central attack surfaces. Defenders should prioritize patching this vendor's advisories given the platform's position in software delivery chains and the access it grants to build artifacts and credentials. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
35
Total CVEs
More Total CVEs than 98% of tracked vendors
4.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by JFrog over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 9, 2016
9 years ago
Most Recent CVE
Aug 5, 2024
718 days ago

Self-Reporting Analysis

Of all the CVEs published by JFrog as a CNA, 16.0% affect products that JFrog develops as a vendor.

16.0%
84.0%
Self-reported: 19 (16.0%)
Third-party: 100 (84.0%)

Of all the CVEs published that affect products developed by JFrog, 54.3% are self-published by JFrog as a CNA.

54.3%
45.7%
Self-published: 19 (54.3%)
Other CNAs: 16 (45.7%)

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (35 CVEs).

35 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-17444CRITICAL
Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attac
Oct 12, 20209.879NOYES
CVE-2019-9733CRITICAL
An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an administrator gets locked out
Apr 11, 20199.866NOYES
CVE-2016-10036CRITICAL
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arb
May 1, 20189.847NOYES
CVE-2018-19971CRITICAL
JFrog Artifactory Pro 6.5.9 has Incorrect Access Control.
Apr 16, 20199.832NONO
CVE-2016-6501CRITICAL
JFrog Artifactory before 4.11 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.
Dec 9, 20169.832NONO
CVE-2022-0668CRITICAL
JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated use
Jan 8, 20239.831NONO
CVE-2024-6915CRITICAL
JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to ca
Aug 5, 20249.330NONO
CVE-2021-23163HIGH
JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog
Jul 6, 20228.828NONO
CVE-2021-3860HIGH
JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when perfor
Dec 20, 20218.828NONO
CVE-2024-4142CRITICAL
An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with low privi
May 1, 20249.026NONO
View all 35 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products35 CVEs
43%
31%
23%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (2.9%)
Network34 (97.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low33 (94.3%)
High2 (5.7%)
Unknown0 (0.0%)
User Interaction
None26 (74.3%)
Unknown0 (0.0%)
Required9 (25.7%)
Privileges Required
Low11 (31.4%)
High5 (14.3%)
None19 (54.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (35 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
5.7% of CVEs· 96th percentile
ExploitDB
1 CVE
2.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by JFrog.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by JFrog — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For JFrog's Products

View all 5 CNAs →

Top CWEs