Element Software
Vendor:
First CVE: Aug 8, 2017 · Active for 8 years
100
Total CVEs
More Total CVEs than 99% of tracked products
12.5
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Element Software over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 8, 2017
8 years ago
Most Recent CVE
Feb 5, 2025
535 days ago
CVE Severity & Scoring
Element Software100 CVEs
45%
31%
17%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local21 (21.0%)
Network76 (76.0%)
Unknown0 (0.0%)
Physical2 (2.0%)
Adjacent Network1 (1.0%)
Attack Complexity
Low63 (63.0%)
High37 (37.0%)
Unknown0 (0.0%)
User Interaction
None67 (67.0%)
Unknown0 (0.0%)
Required33 (33.0%)
Privileges Required
Low19 (19.0%)
High3 (3.0%)
None78 (78.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (100 CVEs).
100 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2068HIGH In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to | Jun 21, 2022 | 7.3 | 76 | NO | NO |
CVE-2018-7182HIGH The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mode 6 packet with a ntpd inst | Mar 6, 2018 | 7.5 | 51 | NO | YES |
CVE-2019-6110MEDIUM In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for ex | Jan 31, 2019 | 6.8 | 44 | NO | YES |
CVE-2022-32206MEDIUM curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number o | Jul 7, 2022 | 6.5 | 39 | NO | NO |
CVE-2017-7657CRITICAL In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled | Jun 26, 2018 | 9.8 | 39 | NO | NO |
CVE-2018-17182HIGH An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An attacker can trigger a use-aft | Sep 19, 2018 | 7.8 | 37 | NO | YES |
CVE-2018-7183CRITICAL Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a respon | Mar 8, 2018 | 9.8 | 36 | NO | NO |
CVE-2019-3462HIGH Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to r | Jan 28, 2019 | 8.1 | 35 | NO | NO |
CVE-2018-6485CRITICAL An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to retu | Feb 1, 2018 | 9.8 | 33 | NO | NO |
CVE-2019-11068CRITICAL libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead | Apr 10, 2019 | 9.8 | 32 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (100 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
5.0% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (100 CVEs).
Media Mentions
Signals from CVEs in this product scope (100 CVEs).
Top CNAs Publishing CVEs For Element Software
Top CWEs
Versions
No cataloged versions.