Blockchain Platform

Vendor:

First CVE: May 29, 2017 · Active for 9 years

40
Total CVEs
More Total CVEs than 97% of tracked products
10.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 48% of tracked products
2.5%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Blockchain Platform over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 29, 2017
9 years ago
Most Recent CVE
Jul 21, 2021
1,830 days ago

CVE Severity & Scoring

Blockchain Platform40 CVEs
All CVEs352,427 CVEs
MediumHigh
Attack Vector
Local1 (2.5%)
Network39 (97.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (35.0%)
High26 (65.0%)
Unknown0 (0.0%)
User Interaction
None36 (90.0%)
Unknown0 (0.0%)
Required4 (10.0%)
Privileges Required
Low3 (7.5%)
High1 (2.5%)
None36 (90.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (40 CVEs).

40 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's
Apr 29, 20206.195YESYES
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append
Apr 29, 20206.183NOYES
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payl
Jul 14, 20207.577NOYES
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in
Jun 1, 20217.765NOYES
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 b
Nov 19, 20207.554NONO
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property
Aug 20, 20197.340NONO
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapte
Jan 7, 20218.136NONO
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the
Dec 3, 20207.534NONO
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The hi
Dec 3, 20207.534NONO
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDICo
Dec 27, 20208.131NONO

Exploit Exposure

Signals from CVEs in this product scope (40 CVEs).

CISA KEV
1 CVE
2.5% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.5% of CVEs· 96th percentile
ExploitDB
3 CVEs
7.5% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (40 CVEs).

Media Mentions

Signals from CVEs in this product scope (40 CVEs).

Top CNAs Publishing CVEs For Blockchain Platform

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
21.1.227.243.2%11