Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Opswat

First CVE: Aug 31, 2018Active for: 8 yearsTotal CVEs: 8

Opswat develops a focused suite of endpoint security and file-validation products, including MetaDefender and MetaDefender Kiosk, that operate in security-critical positions such as web gateways, USB inspection, and threat detection pipelines. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, stemming from recurring weakness classes including improper privilege management, classic buffer overflows, command injection, and cross-site scripting that arise across its threat-scanning and validation components. Defenders should treat this vendor's advisories as high-priority given the sensitive data-handling role of its products; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Opswat over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 31, 2018
7 years ago
Most Recent CVE
Nov 11, 2025
255 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-32272CRITICAL
OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access control, resulting in privilege e
Jun 9, 20229.846NOYES
CVE-2023-36659CRITICAL
An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Long inputs were not properly processed, which allows remote attackers to cause a denial of service (loss of commun
Sep 15, 20239.828NONO
CVE-2023-36657CRITICAL
An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Built-in features of Windows (desktop shortcuts, narrator) can be abused for privilege escalation.
Sep 15, 20239.828NONO
CVE-2018-16275HIGH
OPSWAT MetaDefender before v4.11.2 allows CSV injection.
Aug 31, 20187.825NONO
CVE-2024-57695HIGH
An issue in Agnitum Outpost Security Suite 7.5.3 (3942.608.1810) and 7.6 (3984.693.1842) allows a local attacker to execute arbitrary code via the lock function. The manufacturer f
Nov 11, 20257.724NONO
CVE-2023-36658HIGH
An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. It has an unquoted service path that can be abused locally.
Sep 15, 20237.823NONO
CVE-2022-40778MEDIUM
A stored Cross-Site Scripting (XSS) vulnerability in OPSWAT MetaDefender ICAP Server before 4.13.0 allows attackers to execute arbitrary JavaScript or HTML because of the blocked p
Sep 19, 20225.421NONO
CVE-2022-32273MEDIUM
As a result of an observable discrepancy in returned messages, OPSWAT MetaDefender Core (MDCore) before 5.1.2 could allow an authenticated user to enumerate filenames on the server
Jun 8, 20224.318NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
25%
38%
38%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (37.5%)
Network5 (62.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (75.0%)
Unknown0 (0.0%)
Required2 (25.0%)
Privileges Required
Low3 (37.5%)
High0 (0.0%)
None5 (62.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
12.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Opswat.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Opswat — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Opswat's Products

View all 1 CNAs →

Top CWEs