Field Analytics

Vendor:

First CVE: Jun 12, 2025 · Active for 1 year

12
Total CVEs
More Total CVEs than 90% of tracked products
12.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Field Analytics over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 12, 2025
13 months ago
Most Recent CVE
Jun 12, 2025
407 days ago

CVE Severity & Scoring

Field Analytics12 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (66.7%)
Unknown0 (0.0%)
Required4 (33.3%)
Privileges Required
Low1 (8.3%)
High0 (0.0%)
None11 (91.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it. This allows the attacker to disru
Jun 12, 20259.827NONO
A service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive information, modify data in unexpected ways or spoof identities of ot
Jun 12, 20259.124NONO
A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration settings of the product.
Jun 12, 20257.521NONO
The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downloading and decompressing the backup files.
Jun 12, 20257.520NONO
The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering.
Jun 12, 20257.520NONO
The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be
Jun 12, 20256.118NONO
The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different fr
Jun 12, 20256.118NONO
Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it possible to attack other users
Jun 12, 20256.118NONO
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.
Jun 12, 20256.518NONO
The application is vulnerable to Server-Side Request Forgery (SSRF). An endpoint can be used to send server internal requests to other ports.
Jun 12, 20255.817NONO

Exploit Exposure

Signals from CVEs in this product scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (12 CVEs).

Media Mentions

Signals from CVEs in this product scope (12 CVEs).

Top CNAs Publishing CVEs For Field Analytics

Top CWEs

Versions

No cataloged versions.