Data Integrator

Vendor:

First CVE: Oct 25, 2016 · Active for 9 years

37
Total CVEs
More Total CVEs than 97% of tracked products
5.3
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Data Integrator over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 25, 2016
9 years ago
Most Recent CVE
Jun 16, 2026
38 days ago

CVE Severity & Scoring

Data Integrator37 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local2 (5.4%)
Network35 (94.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (51.4%)
High18 (48.6%)
Unknown0 (0.0%)
User Interaction
None32 (86.5%)
Unknown0 (0.0%)
Required5 (13.5%)
Privileges Required
Low7 (18.9%)
High0 (0.0%)
None30 (81.1%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (37 CVEs).

37 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit
Dec 18, 20215.976NONO
SQL Injection exists in the CheckList 1.1.1 component for Joomla! via the title_search, tag_search, name_search, description_search, or filter_order parameter.
Feb 22, 20189.844NOYES
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no
May 24, 20189.839NONO
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a
Oct 15, 20199.838NONO
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapte
Jan 7, 20218.136NONO
SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the pres
Jan 30, 20179.834NONO
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Cl
Jul 9, 20189.832NONO
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDICo
Dec 27, 20208.131NONO
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDICo
Jan 6, 20218.130NONO
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolD
Jan 6, 20218.130NONO

Exploit Exposure

Signals from CVEs in this product scope (37 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.7% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (37 CVEs).

Media Mentions

Signals from CVEs in this product scope (37 CVEs).

Top CNAs Publishing CVEs For Data Integrator

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
14.1.2.0.018.30.4%00
12.2.1.4.0317.79.3%01
12.2.1.3.0217.29.7%01
12.2.1.1.024.41.5%00
12.2.1.0.024.41.5%00
12.1.3.0.024.41.5%00
12.1.2.0.013.11.3%00
11.1.1.9.077.14.0%01
11.1.1.7.024.41.5%00