Commerce Guided Search

Vendor:

First CVE: Apr 16, 2015 · Active for 11 years

71
Total CVEs
More Total CVEs than 99% of tracked products
8.9
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
2.8%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Commerce Guided Search over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 16, 2015
11 years ago
Most Recent CVE
Jul 21, 2026
7 days ago

CVE Severity & Scoring

Commerce Guided Search71 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local5 (7.0%)
Network65 (91.5%)
Unknown1 (1.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low48 (67.6%)
High22 (31.0%)
Unknown1 (1.4%)
User Interaction
None57 (80.3%)
Unknown1 (1.4%)
Required13 (18.3%)
Privileges Required
Low33 (46.5%)
High1 (1.4%)
None36 (50.7%)
Unknown1 (1.4%)

Top CVEs

Signals from CVEs in this product scope (71 CVEs).

71 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unse
Mar 3, 202210.099YESYES
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute command
Aug 23, 20218.598YESYES
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payl
Jul 14, 20207.577NOYES
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from
Aug 23, 20218.546NOYES
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from
Aug 23, 20218.546NOYES
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources
Aug 23, 20218.544NOYES
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported versi
Jul 21, 20269.839NONO
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version
Jul 21, 20269.939NONO
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version
Jul 21, 20269.839NONO
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is
Jul 21, 20269.137NONO

Exploit Exposure

Signals from CVEs in this product scope (71 CVEs).

CISA KEV
2 CVEs
2.8% of CVEs· 98th percentile
Metasploit
2 CVEs
2.8% of CVEs· 97th percentile
Nuclei
6 CVEs
8.5% of CVEs· 97th percentile
ExploitDB
1 CVE
1.4% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (71 CVEs).

Media Mentions

Signals from CVEs in this product scope (71 CVEs).

Top CNAs Publishing CVEs For Commerce Guided Search

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.5.218.21.4%00
6.5.118.21.4%00
6.5.018.21.4%00
6.4.1.218.21.4%00
6.3.018.21.4%00
6.2.218.21.4%00
11.4.0178.00.3%00
11.3.2487.311.9%26
11.3.1.535.00.7%00