Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Skyboxsecurity

First CVE: May 17, 2014Active for: 12 yearsTotal CVEs: 10
35.4
VTI Score
Medium

Skyboxsecurity maintains a focused portfolio of vulnerability and risk management appliances and platform components, including its Skybox Platform, Manager Client, and View Appliance offerings, that occupy a prominent role in the vulnerability assessment and remediation workflows of enterprise security teams. Vulnerabilities affecting the vendor skew toward serious outcomes and have a moderate tendency toward public exploit availability, with the exposure recurring through application-layer weakness classes including information exposure, input validation failures, cross-site scripting, path traversal, and SQL injection that are characteristic of web-facing management interfaces. Defenders should treat updates for this vendor's core platform and appliance components as high-priority given their central role in vulnerability visibility and remediation orchestration; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Skyboxsecurity over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 17, 2014
12 years ago
Most Recent CVE
Jan 12, 2018
3,115 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-2084HIGH
Skybox View Appliances with ISO 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, and 6.4.46-2.57 does not properly restrict access to the Admin interface, which allows remote at
May 17, 20148.537NOYES
CVE-2015-9249CRITICAL
An issue was discovered in Skybox Platform before 7.5.201. SQL Injection exists in /skyboxview/webservice/services/VersionWebService via a soapenv:Body element.
Jan 12, 20189.830NONO
CVE-2015-9246CRITICAL
An issue was discovered in Skybox Platform before 7.5.201. Remote Unauthenticated Code Execution exists via a WAR archive containing a JSP file. The WAR file is sent to /skyboxview
Jan 12, 20189.830NONO
CVE-2017-14773HIGH
Skybox Manager Client Application prior to 8.5.501 is prone to an elevation of privileges vulnerability during authentication of a valid user in a debugger-pause state. The vulnera
Oct 3, 20177.823NONO
CVE-2015-9250HIGH
An issue was discovered in Skybox Platform before 7.5.201. Directory Traversal exists in /skyboxview/webskybox/attachmentdownload and /skyboxview/webskybox/filedownload via the tem
Jan 12, 20187.519NONO
CVE-2017-14771MEDIUM
Skybox Manager Client Application prior to 8.5.501 is prone to an arbitrary file upload vulnerability due to insufficient input validation of user-supplied files path when uploadin
Oct 3, 20175.518NONO
CVE-2017-14770MEDIUM
Skybox Manager Client Application prior to 8.5.501 is prone to an information disclosure vulnerability of user password hashes. A local authenticated attacker can access the passwo
Oct 3, 20175.518NONO
CVE-2015-9248MEDIUM
An issue was discovered in Skybox Platform before 7.5.201. Stored cross-site scripting vulnerabilities exist in the title, Comments, or Description field to /skyboxview/webskybox/t
Jan 12, 20185.415NONO
CVE-2015-9247MEDIUM
An issue was discovered in Skybox Platform before 7.5.401. Reflected cross-site scripting vulnerabilities exist in /skyboxview/webservice/services/VersionRepositoryWebService via a
Jan 12, 20185.415NONO
CVE-2017-14772LOW
Skybox Manager Client Application is prone to information disclosure via a username enumeration attack. A local unauthenticated attacker could exploit the flaw to obtain valid user
Oct 3, 20173.315NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
10%
40%
30%
20%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (40.0%)
Network5 (50.0%)
Unknown1 (10.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High0 (0.0%)
Unknown1 (10.0%)
User Interaction
None7 (70.0%)
Unknown1 (10.0%)
Required2 (20.0%)
Privileges Required
Low6 (60.0%)
High0 (0.0%)
None3 (30.0%)
Unknown1 (10.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Skyboxsecurity.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Skyboxsecurity — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Skyboxsecurity's Products

View all 1 CNAs →

Top CWEs