Manageability Software Development Kit
Vendor:
First CVE: Dec 24, 2019 · Active for 6 years
15
Total CVEs
More Total CVEs than 92% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Manageability Software Development Kit over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 24, 2019
6 years ago
Most Recent CVE
Feb 18, 2025
521 days ago
CVE Severity & Scoring
Manageability Software Development Kit15 CVEs
33%
47%
20%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (13.3%)
Network13 (86.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (80.0%)
High3 (20.0%)
Unknown0 (0.0%)
User Interaction
None12 (80.0%)
Unknown0 (0.0%)
Required3 (20.0%)
Privileges Required
Low1 (6.7%)
High0 (0.0%)
None14 (93.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3711CRITICAL In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first tim | Aug 24, 2021 | 9.8 | 79 | NO | NO |
CVE-2021-3712HIGH ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This cont | Aug 24, 2021 | 7.4 | 53 | NO | NO |
CVE-2018-1285CRITICAL Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept a | May 11, 2020 | 9.8 | 44 | NO | NO |
CVE-2021-3517HIGH There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application li | May 19, 2021 | 8.6 | 31 | NO | NO |
CVE-2024-56171CRITICAL libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML | Feb 18, 2025 | 9.8 | 30 | NO | NO |
CVE-2022-23308HIGH valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. | Feb 26, 2022 | 7.5 | 28 | NO | NO |
CVE-2021-3518HIGH There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-afte | May 18, 2021 | 8.8 | 28 | NO | NO |
CVE-2022-40304HIGH An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, | Nov 23, 2022 | 7.8 | 27 | NO | NO |
CVE-2019-19956HIGH xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs. | Dec 24, 2019 | 7.5 | 27 | NO | NO |
CVE-2025-24928HIGH libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted doc | Feb 18, 2025 | 7.7 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Manageability Software Development Kit
Top CWEs
Versions
No cataloged versions.