Field Analytics
Vendor:
First CVE: Jun 12, 2025 · Active for 1 year
12
Total CVEs
More Total CVEs than 90% of tracked products
12.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Field Analytics over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 12, 2025
13 months ago
Most Recent CVE
Jun 12, 2025
407 days ago
CVE Severity & Scoring
Field Analytics12 CVEs
58%
25%
17%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (66.7%)
Unknown0 (0.0%)
Required4 (33.3%)
Privileges Required
Low1 (8.3%)
High0 (0.0%)
None11 (91.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-49199CRITICAL The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it. This allows the attacker to disru | Jun 12, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-49196CRITICAL A service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive information, modify data in unexpected ways or spoof identities of ot | Jun 12, 2025 | 9.1 | 24 | NO | NO |
CVE-2025-49184HIGH A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration settings of the product. | Jun 12, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-49200HIGH The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downloading and decompressing the backup files. | Jun 12, 2025 | 7.5 | 20 | NO | NO |
CVE-2025-49188HIGH The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering. | Jun 12, 2025 | 7.5 | 20 | NO | NO |
CVE-2025-49193MEDIUM The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be | Jun 12, 2025 | 6.1 | 18 | NO | NO |
CVE-2025-49192MEDIUM The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different fr | Jun 12, 2025 | 6.1 | 18 | NO | NO |
CVE-2025-49191MEDIUM Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it possible to attack other users | Jun 12, 2025 | 6.1 | 18 | NO | NO |
CVE-2025-49186MEDIUM The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks. | Jun 12, 2025 | 6.5 | 18 | NO | NO |
CVE-2025-49190MEDIUM The application is vulnerable to Server-Side Request Forgery (SSRF). An endpoint can be used to send server internal requests to other ports. | Jun 12, 2025 | 5.8 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Field Analytics
Top CWEs
Versions
No cataloged versions.