Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pax Project

First CVE: Jan 21, 2015Active for: 12 yearsTotal CVEs: 6

The Pax Project develops a hardening patch set for the Linux kernel and userland, with a focused vulnerability footprint centered on its core Pax product and the file-access safeguards it implements. The durable signal in its disclosures reflects the product's role in boundary enforcement: path-traversal and symlink-following weaknesses that can arise in privilege-boundary and filesystem-isolation mechanisms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 56% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 7% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pax Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 21, 2015
11 years ago
Most Recent CVE
Apr 14, 2023
1,197 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-28046HIGH
An issue was discovered in ProlinOS through 2.4.161.8859R. An attacker with local code execution privileges as a normal user (MAINAPP) can escalate to root privileges by exploiting
Nov 2, 20207.824NONO
CVE-2020-28045HIGH
An unsigned-library issue was discovered in ProlinOS through 2.4.161.8859R. This OS requires installed applications and all system binaries to be signed either by the manufacturer
Nov 2, 20207.824NONO
CVE-2023-26980HIGH
PAX Technology PAX A920 Pro PayDroid 8.1suffers from a Race Condition vulnerability, which allows attackers to bypass the payment software and force the OS to boot directly to Andr
Apr 14, 20237.023NONO
CVE-2020-28044MEDIUM
An attacker with physical access to a PAX Point Of Sale device with ProlinOS through 2.4.161.8859R can boot it in management mode, enable the XCB service, and then list, read, crea
Nov 2, 20206.821NONO
CVE-2015-1193MEDIUM
Multiple directory traversal vulnerabilities in pax 1:20140703 allow remote attackers to write to arbitrary files via a (1) full pathname or (2) .. (dot dot) in an archive.
Jan 21, 20155.015NONO
CVE-2015-1194MEDIUM
pax 1:20140703 allows remote attackers to write to arbitrary files via a symlink attack in an archive.
Jan 21, 20154.314NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
50%
50%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local3 (50.0%)
Network0 (0.0%)
Unknown2 (33.3%)
Physical1 (16.7%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (50.0%)
High1 (16.7%)
Unknown2 (33.3%)
User Interaction
None4 (66.7%)
Unknown2 (33.3%)
Required0 (0.0%)
Privileges Required
Low3 (50.0%)
High0 (0.0%)
None1 (16.7%)
Unknown2 (33.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pax Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pax Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pax Project's Products

View all 1 CNAs →

Top CWEs