Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sos

First CVE: Sep 11, 2014Active for: 12 yearsTotal CVEs: 6

SOS develops a modestly represented job-scheduling and automation platform where the observed vulnerability signal centers on web-facing input and path-handling issues, particularly path traversal and cross-site scripting flaws. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 72% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
5.5
Avg CVSS Score
Higher Avg CVSS Score than 8% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sos over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 11, 2014
11 years ago
Most Recent CVE
Sep 1, 2022
1,422 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-5392MEDIUM
XML External Entity (XXE) vulnerability in JobScheduler before 1.6.4246 and 7.x before 1.7.4241 allows remote attackers to cause a denial of service and read arbitrary files or dir
Sep 23, 20145.822NONO
CVE-2022-2806MEDIUM
It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev
Sep 1, 20225.520NONO
CVE-2015-7529HIGH
sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as
Nov 6, 20177.820NONO
CVE-2014-5391MEDIUM
Cross-site scripting (XSS) vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote attackers to inject
Sep 11, 20144.319NONO
CVE-2014-5393MEDIUM
Directory traversal vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote authenticated users with t
Sep 11, 20144.018NONO
CVE-2015-3171MEDIUM
sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ to obtain sensitive information by reading the contents of t
Jul 25, 20175.517NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
83%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local3 (50.0%)
Network0 (0.0%)
Unknown3 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (50.0%)
High0 (0.0%)
Unknown3 (50.0%)
User Interaction
None3 (50.0%)
Unknown3 (50.0%)
Required0 (0.0%)
Privileges Required
Low3 (50.0%)
High0 (0.0%)
None0 (0.0%)
Unknown3 (50.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sos.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sos — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sos's Products

View all 2 CNAs →

Top CWEs