Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Netfoundry

First CVE: Apr 17, 2026Active for: 1 yearTotal CVEs: 6

Netfoundry maintains a focused product portfolio centered on zrok, a zero-trust sharing and tunneling platform that simplifies secure access to internal applications and services. The recurring vulnerability signal spans access-control issues, output-encoding and path-traversal weaknesses, and cross-site scripting flaws that reflect the authentication and input-handling demands of web-facing proxy and sharing infrastructure. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
6.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Netfoundry over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 17, 2026
3 months ago
Most Recent CVE
Jul 16, 2026
8 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-45568CRITICAL
zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path
Jul 16, 20269.138NONO
CVE-2026-45576HIGH
zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores attacker-controlled WebDAV or zrok drive paths such as /../out
Jul 16, 20267.533NONO
CVE-2026-42275HIGH
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.2, the zrok WebDAV drive backend (davServer.Dir) restricts path traversal through lexi
May 8, 20268.733NONO
CVE-2026-40303HIGH
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, endpoints.GetSessionCookie parses an attacker-supplied cookie chunk count and calls
Apr 17, 20267.526NONO
CVE-2026-40302MEDIUM
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template engine uses Go's text/template (which performs no HTML escapin
Apr 17, 20266.122NONO
CVE-2026-40304MEDIUM
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the unaccess handler (controller/unaccess.go) contains a logical error in its owner
Apr 17, 20265.321NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
33%
50%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (66.7%)
High2 (33.3%)
Unknown0 (0.0%)
User Interaction
None5 (83.3%)
Unknown0 (0.0%)
Required1 (16.7%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None5 (83.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Netfoundry.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Netfoundry — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Netfoundry's Products

View all 1 CNAs →

Top CWEs