Marvalglobal's vulnerability profile concentrates in a narrowly scoped portfolio centered on its Marval MSM management platform, yet the vendor appears among more prominent vendors in the vulnerability landscape, suggesting substantial deployment in critical infrastructure or enterprise environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, with exposure recuring through authentication and access-control weaknesses—including authorization bypass, CSRF, and OS command injection—alongside deserialization flaws and weak encryption that characterize the security posture of administrative and management software. Defenders should prioritize Marvalglobal advisories and treat management-tier instances as high-value targets; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Marvalglobal over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-31885CRITICAL Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts. | Jun 28, 2022 | 9.8 | 59 | NO | YES |
CVE-2022-31886MEDIUM Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending the user a malicious form. | Jun 28, 2022 | 6.5 | 32 | NO | YES |
CVE-2022-31887CRITICAL Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, this means that the user can also | Jun 28, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-33284HIGH Marval MSM through 14.19.0.12476 and 15.0 has a Remote Code Execution vulnerability. A remote attacker authenticated as any user is able to execute code in context of the web serve | Jun 7, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-31883HIGH Marval MSM v14.19.0.12476 is has an Insecure Direct Object Reference (IDOR) vulnerability. A low privilege user is able to see other users API Keys including the Admins API Keys. | Jun 28, 2022 | 8.8 | 27 | NO | NO |
CVE-2023-33282CRITICAL Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. A remote attacker is able to login and create a valid session. This makes it possible to ma | Jun 7, 2023 | 9.8 | 24 | NO | NO |
CVE-2022-31884MEDIUM Marval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other users API Keys including high privilege and the Administrat | Jun 28, 2022 | 6.5 | 22 | NO | NO |
CVE-2023-33283MEDIUM Marval MSM through 14.19.0.12476 uses a static encryption key for secrets. An attacker that gains access to encrypted secrets can decrypt them by using this key. | Jun 7, 2023 | 5.5 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Marvalglobal.
Media articles that mention a CVE ID that affects a product developed by Marvalglobal — matched by CVE ID, not by vendor name.