Communications Design Studio
Vendor:
First CVE: Aug 2, 2018 · Active for 7 years
15
Total CVEs
More Total CVEs than 92% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Communications Design Studio over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 2, 2018
7 years ago
Most Recent CVE
Apr 21, 2022
1,558 days ago
CVE Severity & Scoring
Communications Design Studio15 CVEs
67%
33%
All CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (6.7%)
Network13 (86.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (6.7%)
Attack Complexity
Low10 (66.7%)
High5 (33.3%)
Unknown0 (0.0%)
User Interaction
None9 (60.0%)
Unknown0 (0.0%)
Required6 (40.0%)
Privileges Required
Low3 (20.0%)
High1 (6.7%)
None11 (73.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-0227HIGH A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projec | May 1, 2019 | 7.5 | 84 | NO | YES |
CVE-2021-23337HIGH Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. | Feb 15, 2021 | 7.2 | 48 | NO | YES |
CVE-2019-10086HIGH In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property | Aug 20, 2019 | 7.3 | 40 | NO | NO |
CVE-2020-11612HIGH The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream | Apr 7, 2020 | 7.5 | 30 | NO | NO |
CVE-2021-2351HIGH Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulne | Jul 21, 2021 | 8.3 | 28 | NO | NO |
CVE-2020-5421MEDIUM In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 m | Sep 19, 2020 | 6.5 | 27 | NO | NO |
CVE-2018-8032MEDIUM Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services. | Aug 2, 2018 | 6.1 | 26 | NO | NO |
CVE-2021-43797MEDIUM Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71 | Dec 9, 2021 | 6.5 | 24 | NO | NO |
CVE-2021-29425MEDIUM In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, | Apr 13, 2021 | 4.8 | 24 | NO | NO |
CVE-2019-16168MEDIUM In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe divis | Sep 9, 2019 | 6.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
6.7% of CVEs· 97th percentile
ExploitDB
1 CVE
6.7% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Communications Design Studio
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.4.2.0.0 | 2 | 6.5 | 13.1% | 0 | 1 |
| 7.4.2 | 7 | 6.5 | 3.9% | 0 | 0 |
| 7.4.1.1.0 | 2 | 6.8 | 51.2% | 0 | 1 |
| 7.4.1 | 2 | 7.2 | 2.3% | 0 | 0 |
| 7.4.0.4.0 | 3 | 6.7 | 35.6% | 0 | 1 |
| 7.4.0 | 4 | 7.0 | 11.3% | 0 | 0 |
| 7.3.5.5.0 | 3 | 6.7 | 35.6% | 0 | 1 |
| 7.3.5 | 5 | 6.6 | 11.1% | 0 | 0 |
| 7.3.4.3.0 | 3 | 6.7 | 35.6% | 0 | 1 |
| 7.3.4 | 3 | 6.6 | 14.2% | 0 | 0 |