Banking Virtual Account Management

Vendor:

First CVE: Apr 17, 2019 · Active for 7 years

39
Total CVEs
More Total CVEs than 98% of tracked products
7.8
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 72% of tracked products
2.6%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Banking Virtual Account Management over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 17, 2019
7 years ago
Most Recent CVE
Apr 18, 2023
1,197 days ago

CVE Severity & Scoring

Banking Virtual Account Management39 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local2 (5.1%)
Network37 (94.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (48.7%)
High20 (51.3%)
Unknown0 (0.0%)
User Interaction
None31 (79.5%)
Unknown0 (0.0%)
Required8 (20.5%)
Privileges Required
Low2 (5.1%)
High7 (17.9%)
None30 (76.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (39 CVEs).

39 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a r
Apr 1, 20229.899YESYES
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arb
Mar 23, 20219.182NOYES
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processe
Nov 16, 20208.882NOYES
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficien
Mar 23, 20219.980NOYES
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execu
Mar 23, 20219.874NONO
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execu
Mar 23, 20219.873NONO
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time co
Mar 23, 20219.155NONO
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data f
Mar 23, 20218.653NONO
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time co
Mar 23, 20217.550NONO
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitr
Mar 23, 20219.838NONO

Exploit Exposure

Signals from CVEs in this product scope (39 CVEs).

CISA KEV
1 CVE
2.6% of CVEs· 98th percentile
Metasploit
1 CVE
2.6% of CVEs· 97th percentile
Nuclei
4 CVEs
10.3% of CVEs· 97th percentile
ExploitDB
1 CVE
2.6% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (39 CVEs).

Media Mentions

Signals from CVEs in this product scope (39 CVEs).

Top CNAs Publishing CVEs For Banking Virtual Account Management

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
14.765.80.5%00
14.665.80.5%00
14.5.0308.323.8%03
14.586.814.0%11
14.4.017.53.9%00
14.3.0328.322.7%03
14.2.0308.323.8%03
14.219.89.4%00
14.1.017.53.9%00