Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ritlabs

First CVE: Jun 18, 2001Active for: 25 yearsTotal CVEs: 16
40.9
VTI Score
High

Ritlabs develops email and web server software with a focused product line centered on The Bat email client and TinyWeb web server, components that occupy a notable position despite modest production volume. Vulnerabilities affecting the vendor skew toward critical severity and frequently acquire public exploit code; the recurring weakness classes span resource-exhaustion conditions, injection flaws across CRLF and OS-command contexts, and NVD placeholder categorizations that reflect the diversity of flaw types encountered. Defenders should monitor this vendor's advisories closely and prioritize patching for internet-facing server instances; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ritlabs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 18, 2001
25 years ago
Most Recent CVE
Mar 6, 2026
140 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-22781CRITICAL
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable to OS command injection via CGI ISINDEX-style query paramet
Jan 12, 20269.835NONO
CVE-2026-27613CRITICAL
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. A vulnerability in versions prior to 2.01 allows unauthenticated remote attackers to bypass the web server's CGI
Feb 25, 20269.832NONO
CVE-2001-0675MEDIUM
Rit Research Labs The Bat! 1.51 for Windows allows a remote attacker to cause a denial of service by sending an email to a user's account containing a carriage return <CR> that is
Sep 20, 20015.029NOYES
CVE-2026-28497CRITICAL
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.03, an integer overflow vulnerability in the string-to-integer conversion routine (_Val) allow
Mar 6, 20269.128NONO
CVE-2026-29046HIGH
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header values and later maps them into CGI environment variables (
Mar 6, 20268.226NONO
CVE-2026-27633HIGH
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 have a Denial of Service (DoS) vulnerability via memory exhaustion. Unauthenticate
Feb 26, 20267.525NONO
CVE-2026-27630HIGH
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 are vulnerable to a Denial of Service (DoS) attack known as Slowloris. The server
Feb 26, 20267.525NONO
CVE-2001-0398HIGH
The BAT! mail client allows remote attackers to bypass user warnings of an executable attachment and execute arbitrary commands via an attachment whose file name contains many spac
Jun 18, 20017.524NONO
CVE-2024-34199HIGH
TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sending excessively large elements in the request line.
May 14, 20248.623NONO
CVE-2002-0338MEDIUM
The Bat! 1.53d and 1.54beta, and possibly other versions, allows remote attackers to cause a denial of service (crash) via an attachment whose name includes an MS-DOS device name.
Jun 25, 20025.023NOYES
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
38%
38%
19%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (56.3%)
Unknown7 (43.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (50.0%)
High1 (6.3%)
Unknown7 (43.8%)
User Interaction
None9 (56.3%)
Unknown7 (43.8%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None9 (56.3%)
Unknown7 (43.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
12.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ritlabs.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ritlabs — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ritlabs's Products

View all 3 CNAs →

Top CWEs