Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nic

First CVE: Jan 22, 2018Active for: 9 yearsTotal CVEs: 19
42.0
VTI Score
High

Nic maintains a focused set of critical DNS and network infrastructure products including Knot Resolver, BIRD, Foris, and Knot CMS that operate in trusted network positions and often handle untrusted input at scale. Vulnerabilities affecting the vendor concentrate in input-validation and resource-management classes—such as improper input validation, unthrottled resource allocation, and inefficient algorithmic complexity—that are characteristic of protocol-parsing and routing software operating under high or adversarial load, and tend toward moderate severity outcomes. Defenders should prioritize updates for these infrastructure components, particularly resolver and routing implementations; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nic over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 22, 2018
8 years ago
Most Recent CVE
Jun 2, 2026
53 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-50387HIGH
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more D
Feb 14, 20247.578NONO
CVE-2021-3346CRITICAL
Foris before 101.1.1, as used in Turris OS, lacks certain HTML escaping in the login template.
Jan 29, 20219.828NONO
CVE-2022-40188HIGH
Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must
Sep 23, 20227.527NONO
CVE-2026-49943MEDIUM
CZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP AS_PATH mask matching implementation in nest/a-path.c. The as_path_match() func
Jun 2, 20266.325NONO
CVE-2019-19331HIGH
knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might be processed very inefficientl
Dec 16, 20197.525NONO
CVE-2019-16159HIGH
BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon's support for RFC 8203 administrative shutdown communicatio
Sep 9, 20197.525NONO
CVE-2019-10191HIGH
A vulnerability was discovered in DNS resolver of knot resolver before version 4.1.0 which allows remote attackers to downgrade DNSSEC-secure domains to DNSSEC-insecure state, open
Jul 16, 20197.525NONO
CVE-2019-10190HIGH
A vulnerability was discovered in DNS resolver component of knot resolver through version 3.2.0 before 4.1.0 which allows remote attackers to bypass DNSSEC validation for non-exist
Jul 16, 20197.525NONO
CVE-2021-40083HIGH
Knot Resolver before 5.3.2 is prone to an assertion failure, triggerable by a remote attacker in an edge case (NSEC3 with too many iterations used for a positive wildcard proof).
Aug 25, 20217.524NONO
CVE-2018-1110HIGH
A flaw was found in knot-resolver before version 2.3.0. Malformed DNS messages may cause denial of service.
Mar 30, 20217.524NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
26%
63%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (73.7%)
High5 (26.3%)
Unknown0 (0.0%)
User Interaction
None19 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (10.5%)
High0 (0.0%)
None17 (89.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nic.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nic — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nic's Products

View all 3 CNAs →

Top CWEs