Management Services For Element Software
Vendor:
First CVE: Feb 26, 2021 · Active for 5 years
27
Total CVEs
More Total CVEs than 96% of tracked products
9.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Management Services For Element Software over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 26, 2021
5 years ago
Most Recent CVE
Aug 7, 2023
1,082 days ago
CVE Severity & Scoring
Management Services For Element Software27 CVEs
26%
67%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (11.1%)
Network24 (88.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (81.5%)
High5 (18.5%)
Unknown0 (0.0%)
User Interaction
None25 (92.6%)
Unknown0 (0.0%)
Required2 (7.4%)
Privileges Required
Low10 (37.0%)
High1 (3.7%)
None16 (59.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-28169MEDIUM For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB | Jun 9, 2021 | 5.3 | 74 | NO | YES |
CVE-2020-27223MEDIUM In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality | Feb 26, 2021 | 5.3 | 61 | NO | NO |
CVE-2018-25032HIGH zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. | Mar 25, 2022 | 7.5 | 56 | NO | NO |
CVE-2022-37434CRITICAL zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHe | Aug 5, 2022 | 9.8 | 41 | NO | NO |
CVE-2023-24329HIGH An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters. | Feb 17, 2023 | 7.5 | 35 | NO | NO |
CVE-2021-32626HIGH Redis is an open source, in-memory database that persists on disk. In affected versions specially crafted Lua scripts executing in Redis can cause the heap-based Lua stack to be ov | Oct 4, 2021 | 8.8 | 35 | NO | NO |
CVE-2021-32675HIGH Redis is an open source, in-memory database that persists on disk. When parsing an incoming Redis Standard Protocol (RESP) request, Redis allocates memory according to user-specifi | Oct 4, 2021 | 7.5 | 32 | NO | NO |
CVE-2021-32628HIGH Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the ziplist data structure used by all versions of Redis can be exploited to corrupt t | Oct 4, 2021 | 7.5 | 31 | NO | NO |
CVE-2023-37920CRITICAL Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023 | Jul 25, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-38023HIGH Netlogon RPC Elevation of Privilege Vulnerability | Nov 9, 2022 | 8.1 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (27 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.7% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (27 CVEs).
Media Mentions
Signals from CVEs in this product scope (27 CVEs).
Top CNAs Publishing CVEs For Management Services For Element Software
Top CWEs
Versions
No cataloged versions.