Fuse

Vendor:

First CVE: Feb 17, 2015 · Active for 11 years

29
Total CVEs
More Total CVEs than 96% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
10.3%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Fuse over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 17, 2015
11 years ago
Most Recent CVE
Jun 10, 2026
44 days ago

CVE Severity & Scoring

Fuse29 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local3 (10.3%)
Network26 (89.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (82.8%)
High5 (17.2%)
Unknown0 (0.0%)
User Interaction
None24 (82.8%)
Unknown0 (0.0%)
Required5 (17.2%)
Privileges Required
Low4 (13.8%)
High2 (6.9%)
None23 (79.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation
Oct 4, 20178.199YESYES
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access rest
Jun 7, 20169.899YESYES
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell comm
Feb 17, 20159.899YESYES
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payloa
Apr 17, 20179.886NOYES
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a si
Apr 6, 20189.872NONO
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header
Jan 7, 20269.638NONO
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to
Mar 27, 20269.135NONO
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain
Mar 27, 20269.135NONO
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping t
Mar 27, 20269.134NONO
JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly t
Jun 10, 20268.133NONO

Exploit Exposure

Signals from CVEs in this product scope (29 CVEs).

CISA KEV
3 CVEs
10.3% of CVEs· 97th percentile
Metasploit
3 CVEs
10.3% of CVEs· 97th percentile
Nuclei
4 CVEs
13.8% of CVEs· 97th percentile
ExploitDB
3 CVEs
10.3% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (29 CVEs).

Media Mentions

Signals from CVEs in this product scope (29 CVEs).

Top CNAs Publishing CVEs For Fuse

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.5.017.82.7%00
7.3.018.82.4%00
7.1116.70.3%00
7.0.078.40.9%00
6.0.016.51.5%00
1.0.048.347.1%11
1.0127.425.4%23