Bluexp
Vendor:
First CVE: Oct 13, 2022 · Active for 3 years
12
Total CVEs
More Total CVEs than 90% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Bluexp over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 13, 2022
3 years ago
Most Recent CVE
Oct 3, 2024
659 days ago
CVE Severity & Scoring
Bluexp12 CVEs
17%
33%
42%
8%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (58.3%)
High5 (41.7%)
Unknown0 (0.0%)
User Interaction
None11 (91.7%)
Unknown0 (0.0%)
Required1 (8.3%)
Privileges Required
Low0 (0.0%)
High1 (8.3%)
None11 (91.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-42889CRITICAL Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where | Oct 13, 2022 | 9.8 | 95 | NO | YES |
CVE-2024-25617HIGH Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into Unsafe Value bug ,Squid may be vulnerable to a Denial of Ser | Feb 14, 2024 | 7.5 | 72 | NO | NO |
CVE-2024-25111HIGH Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack against HTTP Chunked decoder due to an uncont | Mar 6, 2024 | 7.5 | 55 | NO | NO |
CVE-2024-7254HIGH Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. Stac | Sep 19, 2024 | 7.5 | 25 | NO | NO |
CVE-2024-21147HIGH Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected | Jul 16, 2024 | 7.4 | 23 | NO | NO |
CVE-2024-22201HIGH Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many con | Feb 26, 2024 | 7.5 | 23 | NO | NO |
CVE-2024-47554MEDIUM Uncontrolled Resource Consumption vulnerability in Apache Commons IO.
The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing m | Oct 3, 2024 | 4.3 | 18 | NO | NO |
CVE-2024-21145MEDIUM Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are | Jul 16, 2024 | 4.8 | 16 | NO | NO |
CVE-2024-21140MEDIUM Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected | Jul 16, 2024 | 4.8 | 16 | NO | NO |
CVE-2024-21055MEDIUM Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior. Easily exploitable vulnerabili | Apr 16, 2024 | 4.9 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
8.3% of CVEs· 97th percentile
Nuclei
1 CVE
8.3% of CVEs· 97th percentile
ExploitDB
1 CVE
8.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Bluexp
Top CWEs
Versions
No cataloged versions.