Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Marvalglobal

First CVE: Jun 28, 2022Active for: 4 yearsTotal CVEs: 8

Marvalglobal's vulnerability profile concentrates in a narrowly scoped portfolio centered on its Marval MSM management platform, yet the vendor appears among more prominent vendors in the vulnerability landscape, suggesting substantial deployment in critical infrastructure or enterprise environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, with exposure recuring through authentication and access-control weaknesses—including authorization bypass, CSRF, and OS command injection—alongside deserialization flaws and weak encryption that characterize the security posture of administrative and management software. Defenders should prioritize Marvalglobal advisories and treat management-tier instances as high-value targets; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Marvalglobal over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 28, 2022
4 years ago
Most Recent CVE
Jun 7, 2023
1,143 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-31885CRITICAL
Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.
Jun 28, 20229.859NOYES
CVE-2022-31886MEDIUM
Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending the user a malicious form.
Jun 28, 20226.532NOYES
CVE-2022-31887CRITICAL
Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, this means that the user can also
Jun 28, 20229.831NONO
CVE-2023-33284HIGH
Marval MSM through 14.19.0.12476 and 15.0 has a Remote Code Execution vulnerability. A remote attacker authenticated as any user is able to execute code in context of the web serve
Jun 7, 20238.827NONO
CVE-2022-31883HIGH
Marval MSM v14.19.0.12476 is has an Insecure Direct Object Reference (IDOR) vulnerability. A low privilege user is able to see other users API Keys including the Admins API Keys.
Jun 28, 20228.827NONO
CVE-2023-33282CRITICAL
Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. A remote attacker is able to login and create a valid session. This makes it possible to ma
Jun 7, 20239.824NONO
CVE-2022-31884MEDIUM
Marval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other users API Keys including high privilege and the Administrat
Jun 28, 20226.522NONO
CVE-2023-33283MEDIUM
Marval MSM through 14.19.0.12476 uses a static encryption key for secrets. An attacker that gains access to encrypted secrets can decrypt them by using this key.
Jun 7, 20235.515NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
38%
25%
38%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (12.5%)
Network7 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (87.5%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low4 (50.0%)
High0 (0.0%)
None4 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
25.0% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Marvalglobal.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Marvalglobal — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Marvalglobal's Products

View all 1 CNAs →

Top CWEs