Active Iq Unified Manager

Vendor:

First CVE: Feb 3, 2017 · Active for 9 years

848
Total CVEs
More Total CVEs than 100% of tracked products
94.2
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 23% of tracked products
1.1%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Active Iq Unified Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 3, 2017
9 years ago
Most Recent CVE
Apr 15, 2025
469 days ago

CVE Severity & Scoring

Active Iq Unified Manager848 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local88 (10.4%)
Network726 (85.6%)
Unknown0 (0.0%)
Physical20 (2.4%)
Adjacent Network14 (1.7%)
Attack Complexity
Low630 (74.3%)
High218 (25.7%)
Unknown0 (0.0%)
User Interaction
None715 (84.3%)
Unknown0 (0.0%)
Required133 (15.7%)
Privileges Required
Low141 (16.6%)
High274 (32.3%)
None433 (51.1%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (848 CVEs).

848 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai
Dec 10, 202110.099YESYES
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg
Jan 26, 20217.899YESYES
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention
Aug 22, 20188.199YESYES
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation
Oct 4, 20178.199YESYES
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML pag
Sep 12, 20238.896YESNO
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's
Apr 29, 20206.195YESYES
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows
Jul 17, 20197.893YESYES
7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User i
Jan 25, 20257.089YESNO
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth
Jul 1, 20248.189NOYES
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT charac
Apr 17, 20247.387NOYES

Exploit Exposure

Signals from CVEs in this product scope (848 CVEs).

CISA KEV
9 CVEs
1.1% of CVEs· 97th percentile
Metasploit
6 CVEs
0.7% of CVEs· 96th percentile
Nuclei
9 CVEs
1.1% of CVEs· 96th percentile
ExploitDB
10 CVEs
1.2% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (848 CVEs).

Media Mentions

Signals from CVEs in this product scope (848 CVEs).

Top CNAs Publishing CVEs For Active Iq Unified Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.615.39.4%00
9.1015.30.5%00