Discovery
Vendor:
First CVE: Mar 31, 2020 · Active for 6 years
5
Total CVEs
More Total CVEs than 77% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 46% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Discovery over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 31, 2020
6 years ago
Most Recent CVE
Jun 9, 2026
46 days ago
CVE Severity & Scoring
Discovery5 CVEs
20%
80%
All CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (40.0%)
Network3 (60.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (80.0%)
High1 (20.0%)
Unknown0 (0.0%)
User Interaction
None5 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (20.0%)
High0 (0.0%)
None4 (80.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2025-71319HIGH image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image | Jun 9, 2026 | 7.5 | 31 | NO | NO |
CVE-2025-13601HIGH A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a ver | Nov 26, 2025 | 7.7 | 30 | NO | NO |
CVE-2024-12088HIGH A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symb | Jan 14, 2025 | 7.5 | 28 | NO | NO |
CVE-2020-1712HIGH A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged | Mar 31, 2020 | 7.8 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
20.0% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Discovery
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0 | 2 | 7.6 | 0.5% | 0 | 0 |
| 1.14 | 1 | 7.5 | 4.7% | 0 | 0 |