Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Softnext

First CVE: Oct 31, 2022Active for: 4 yearsTotal CVEs: 9

Softnext develops a focused portfolio of mail and threat-management appliances—including Mail SQR Expert, SN OS, and Spam SQR—that operate at the network perimeter and serve as centralized security gateways. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through injection and traversal weakness classes—OS command injection, code injection, path traversal, and server-side request forgery—that are characteristic of internet-facing mail and filtering middleware processing untrusted input. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Softnext over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 31, 2022
3 years ago
Most Recent CVE
Jul 29, 2024
725 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-5670CRITICAL
The web services of Softnext's products, Mail SQR Expert and Mail Archiving Expert do not properly validate user input, allowing unauthenticated remote attackers to inject arbitrar
Jul 29, 20249.831NONO
CVE-2022-40741CRITICAL
Mail SQR Expert’s specific function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerability to perform arbitrary system
Oct 31, 20229.831NONO
CVE-2023-48380HIGH
Softnext Mail SQR Expert is an email management platform, it has insufficient filtering for a special character within a spcific function. A remote attacker authenticated as a loca
Dec 15, 20238.023NONO
CVE-2023-24835HIGH
Softnext Technologies Corp.’s SPAM SQR has a vulnerability of Code Injection within its specific function. An authenticated remote attacker with administrator privilege can exploit
Mar 27, 20237.223NONO
CVE-2022-40742MEDIUM
Mail SQR Expert system has a Local File Inclusion vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary PHP file with .asp file exte
Oct 31, 20226.523NONO
CVE-2023-48382MEDIUM
Softnext Mail SQR Expert is an email management platform, it has a Local File Inclusion (LFI) vulnerability in a mail deliver-related URL. An unauthenticated remote attacker can ex
Dec 15, 20236.520NONO
CVE-2023-48381MEDIUM
Softnext Mail SQR Expert is an email management platform, it has a Local File Inclusion (LFI) vulnerability in a special URL. An unauthenticated remote attacker can exploit this vu
Dec 15, 20236.520NONO
CVE-2023-48378HIGH
Softnext Mail SQR Expert has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can exploit this vulnerability to bypass auth
Dec 15, 20237.519NONO
CVE-2023-48379MEDIUM
Softnext Mail SQR Expert is an email management platform, it has inadequate filtering for a specific URL parameter within a specific function. An unauthenticated remote attacker ca
Dec 15, 20235.318NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
44%
33%
22%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (88.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (11.1%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (11.1%)
High1 (11.1%)
None7 (77.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Softnext.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Softnext — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Softnext's Products

View all 1 CNAs →

Top CWEs