Plixer develops a focused suite of network visibility and flow analytics products, most notably Scrutinizer, which is deployed in environments requiring deep inspection of network traffic patterns and NetFlow/sFlow data. Vulnerabilities affecting these products skew toward serious outcomes and frequently acquire public exploit code, centering on application-layer weaknesses including SQL injection, cross-site scripting, improper authentication, and sensitive-data logging that are characteristic of web-facing analytics platforms. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Plixer over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1259CRITICAL Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allow remote attack | Jan 9, 2020 | 9.8 | 42 | NO | YES |
CVE-2012-1258MEDIUM cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate user permissions, which allow remote attackers to add user a | Jan 9, 2020 | 6.5 | 32 | NO | YES |
CVE-2012-1261MEDIUM Cross-site scripting (XSS) vulnerability in cgi-bin/scrut_fa_exclusions.cgi in Plixer International Scrutinizer NetFlow and sFlow Analyzer 8.6.2.16204 and other versions before 9.0 | Jan 9, 2020 | 6.1 | 31 | NO | YES |
CVE-2012-1260MEDIUM Cross-site scripting (XSS) vulnerability in cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1 | Jan 9, 2020 | 6.1 | 31 | NO | YES |
CVE-2023-41262CRITICAL An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint action generateCSV is vulnerable to SQL injection through the sor | Oct 12, 2023 | 9.8 | 27 | NO | NO |
CVE-2021-28993HIGH Plixer Scrutinizer 19.0.2 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). | Jun 30, 2021 | 7.5 | 25 | NO | NO |
CVE-2023-41261MEDIUM An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint action generateCSV does not require authentication and allows an | Oct 12, 2023 | 5.3 | 15 | NO | NO |
An issue was discovered in Plixer Scrutinizer before 19.3.1. It exposes debug logs to unauthenticated users at the /debug/ URL path. With knowledge of valid IP addresses and source | Oct 12, 2023 | 3.7 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Plixer.
Media articles that mention a CVE ID that affects a product developed by Plixer — matched by CVE ID, not by vendor name.