Satellite
Vendor:
First CVE: Mar 30, 2007 · Active for 19 years
232
Total CVEs
More Total CVEs than 100% of tracked products
13.6
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 31% of tracked products
1.7%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Satellite over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 30, 2007
19 years ago
Most Recent CVE
Jul 1, 2026
26 days ago
CVE Severity & Scoring
Satellite232 CVEs
12%
49%
26%
13%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local24 (10.3%)
Network191 (82.3%)
Unknown16 (6.9%)
Physical0 (0.0%)
Adjacent Network1 (0.4%)
Attack Complexity
Low150 (64.7%)
High66 (28.4%)
Unknown16 (6.9%)
User Interaction
None143 (61.6%)
Unknown16 (6.9%)
Required73 (31.5%)
Privileges Required
Low50 (21.6%)
High14 (6.0%)
None152 (65.5%)
Unknown16 (6.9%)
Top CVEs
Signals from CVEs in this product scope (232 CVEs).
232 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2016-3427CRITICAL Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and avai | Apr 21, 2016 | 9.8 | 95 | YES | NO |
CVE-2015-2590CRITICAL Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability | Jul 16, 2015 | 9.8 | 79 | YES | NO |
CVE-2018-10931CRITICAL It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privile | Aug 9, 2018 | 9.8 | 69 | NO | NO |
CVE-2015-4902MEDIUM Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment. | Oct 22, 2015 | 5.3 | 57 | YES | NO |
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remot | Apr 1, 2015 | 3.7 | 52 | NO | NO |
CVE-2019-2684MEDIUM Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java | Apr 23, 2019 | 5.9 | 40 | NO | NO |
CVE-2026-5136HIGH A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an authenticated user wi | Jul 1, 2026 | 8.8 | 39 | NO | NO |
CVE-2019-2698HIGH Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability a | Apr 23, 2019 | 8.1 | 35 | NO | YES |
CVE-2019-2697HIGH Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability a | Apr 23, 2019 | 8.1 | 35 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (232 CVEs).
CISA KEV
4 CVEs
1.7% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
2.2% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (232 CVEs).
Media Mentions
Signals from CVEs in this product scope (232 CVEs).
Top CNAs Publishing CVEs For Satellite
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.9 | 1 | 4.5 | 0.7% | 0 | 0 |
| 6.8 | 1 | 5.3 | 2.3% | 0 | 0 |
| 6.7.2 | 1 | 7.5 | 0.8% | 0 | 0 |
| 6.7 | 2 | 7.3 | 0.7% | 0 | 0 |
| 6.6 | 2 | 7.0 | 4.1% | 0 | 0 |
| 6.5 | 1 | 7.4 | 6.2% | 0 | 0 |
| 6.4 | 14 | 7.2 | 2.7% | 0 | 0 |
| 6.3 | 6 | 7.0 | 1.7% | 0 | 0 |
| 6.19 | 2 | 7.0 | 0.1% | 0 | 0 |
| 6.18 | 1 | 6.5 | 0.4% | 0 | 0 |
| 6.17 | 1 | 6.5 | 0.4% | 0 | 0 |
| 6.16 | 1 | 6.5 | 0.4% | 0 | 0 |
| 6.15 | 3 | 8.7 | 0.6% | 0 | 0 |
| 6.14 | 2 | 9.8 | 0.8% | 0 | 0 |
| 6.13 | 3 | 8.3 | 0.7% | 0 | 0 |
| 6.11 | 1 | 4.5 | 0.7% | 0 | 0 |
| 6.10 | 1 | 4.5 | 0.7% | 0 | 0 |
| 6.1 | 2 | 6.5 | 1.5% | 0 | 0 |
| 6.0.3 | 1 | 6.1 | 0.6% | 0 | 0 |
| 6.0 | 34 | 6.6 | 4.0% | 1 | 1 |