MITRE Corporation, in its role as a CVE Numbering Authority and operator of vulnerability-cataloging infrastructure, maintains a modest product portfolio that includes the CALDERA adversary-emulation platform, CVE services components, and related security tooling. The recurring weakness classes—principally input-validation gaps, authentication-bypass conditions, cross-site scripting, code injection, and cleartext storage—reflect the attack surface of web-facing and administrative interfaces common to security platforms and infrastructure software. Defenders should treat MITRE's advisories as relevant to their own vulnerability-management and threat-intelligence workflows; live severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by MITRE Corporation over time
Of all the CVEs published by MITRE Corporation as a CNA, 0.0% affect products that MITRE Corporation develops as a vendor.
Of all the CVEs published that affect products developed by MITRE Corporation, 93.3% are self-published by MITRE Corporation as a CNA.
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-27364CRITICAL In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilation functionality of the serve | Feb 24, 2025 | 10.0 | 46 | NO | NO |
CVE-2021-42561HIGH An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. This allows attackers to use shel | Jan 12, 2022 | 8.8 | 37 | NO | NO |
CVE-2008-4704HIGH PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the IP parameter. | Oct 23, 2008 | 10.0 | 36 | NO | YES |
CVE-2021-42560HIGH An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG documents are parsed in an unsafe ma | Jan 12, 2022 | 8.8 | 28 | NO | NO |
CVE-2020-19907HIGH A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service. | Jul 12, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-42559HIGH An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the | Jan 12, 2022 | 8.8 | 27 | NO | NO |
CVE-2021-42562HIGH An issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users having access to read and modify configuration or other compo | Jan 12, 2022 | 8.1 | 26 | NO | NO |
CVE-2022-31004HIGH CVEProject/cve-services is an open source project used to operate the CVE services API. A conditional in 'data.js' has potential for production secrets to be written to disk. The a | Jun 2, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-46561HIGH controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizational administrator to transfer a user | Jan 26, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-40606MEDIUM MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40605. | Oct 17, 2022 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by MITRE Corporation.
Media articles that mention a CVE ID that affects a product developed by MITRE Corporation — matched by CVE ID, not by vendor name.