Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

MITRE Corporation

First CVE: Oct 23, 2008Active for: 18 yearsTotal CVEs: 15
42.2
VTI Score
High

MITRE Corporation, in its role as a CVE Numbering Authority and operator of vulnerability-cataloging infrastructure, maintains a modest product portfolio that includes the CALDERA adversary-emulation platform, CVE services components, and related security tooling. The recurring weakness classes—principally input-validation gaps, authentication-bypass conditions, cross-site scripting, code injection, and cleartext storage—reflect the attack surface of web-facing and administrative interfaces common to security platforms and infrastructure software. Defenders should treat MITRE's advisories as relevant to their own vulnerability-management and threat-intelligence workflows; live severity, exploitation, and exposure details are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by MITRE Corporation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 23, 2008
17 years ago
Most Recent CVE
Feb 24, 2025
515 days ago

Self-Reporting Analysis

Of all the CVEs published by MITRE Corporation as a CNA, 0.0% affect products that MITRE Corporation develops as a vendor.

100.0%
Self-reported: 14 (0.0%)
Third-party: 114,056 (100.0%)

Of all the CVEs published that affect products developed by MITRE Corporation, 93.3% are self-published by MITRE Corporation as a CNA.

93.3%
Self-published: 14 (93.3%)
Other CNAs: 1 (6.7%)

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-27364CRITICAL
In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilation functionality of the serve
Feb 24, 202510.046NONO
CVE-2021-42561HIGH
An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. This allows attackers to use shel
Jan 12, 20228.837NONO
CVE-2008-4704HIGH
PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the IP parameter.
Oct 23, 200810.036NOYES
CVE-2021-42560HIGH
An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG documents are parsed in an unsafe ma
Jan 12, 20228.828NONO
CVE-2020-19907HIGH
A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service.
Jul 12, 20218.828NONO
CVE-2021-42559HIGH
An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the
Jan 12, 20228.827NONO
CVE-2021-42562HIGH
An issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users having access to read and modify configuration or other compo
Jan 12, 20228.126NONO
CVE-2022-31004HIGH
CVEProject/cve-services is an open source project used to operate the CVE services API. A conditional in 'data.js' has potential for production secrets to be written to disk. The a
Jun 2, 20227.524NONO
CVE-2021-46561HIGH
controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizational administrator to transfer a user
Jan 26, 20227.224NONO
CVE-2022-40606MEDIUM
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40605.
Oct 17, 20226.122NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
40%
53%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (93.3%)
Unknown1 (6.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (93.3%)
High0 (0.0%)
Unknown1 (6.7%)
User Interaction
None9 (60.0%)
Unknown1 (6.7%)
Required5 (33.3%)
Privileges Required
Low7 (46.7%)
High1 (6.7%)
None6 (40.0%)
Unknown1 (6.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
6.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by MITRE Corporation.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by MITRE Corporation — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For MITRE Corporation's Products

View all 2 CNAs →

Top CWEs