Banking Apis

Vendor:

First CVE: Oct 10, 2019 · Active for 6 years

14
Total CVEs
More Total CVEs than 92% of tracked products
4.7
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 38% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Banking Apis over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 10, 2019
6 years ago
Most Recent CVE
Nov 17, 2021
1,714 days ago

CVE Severity & Scoring

Banking Apis14 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (85.7%)
High2 (14.3%)
Unknown0 (0.0%)
User Interaction
None10 (71.4%)
Unknown0 (0.0%)
Required4 (28.6%)
Privileges Required
Low2 (14.3%)
High1 (7.1%)
None11 (78.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources withi
Apr 1, 20215.386NOYES
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The hi
Dec 3, 20207.534NONO
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input f
Oct 10, 20199.833NONO
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This
Jul 13, 20217.531NONO
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This
Jul 13, 20217.529NONO
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulne
Jul 21, 20218.328NONO
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could
Feb 24, 20218.228NONO
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the who
Oct 19, 20217.527NONO
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All
Oct 19, 20217.527NONO
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value,
Apr 13, 20214.824NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.1% of CVEs· 97th percentile
Nuclei
1 CVE
7.1% of CVEs· 97th percentile
ExploitDB
1 CVE
7.1% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Banking Apis

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
21.1146.712.6%01
20.1146.712.6%01
19.2127.17.5%00
19.1127.17.5%00
18.336.48.7%00
18.225.56.2%00
18.125.56.2%00