Sphinxsearch develops a search engine and indexing platform that, despite a narrow product scope centered on the Sphinx search product, occupies a niche role in applications requiring full-text search functionality. The observed vulnerability disclosures cluster around authentication and access-control weaknesses, particularly missing authentication checks on critical functions and path-traversal conditions that could permit unauthorized file access. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sphinxsearch over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14511HIGH Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen | Aug 22, 2019 | 7.5 | 25 | NO | NO |
CVE-2020-29050HIGH SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can be used for CALL SNIPPETS and | Jan 10, 2022 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sphinxsearch.
Media articles that mention a CVE ID that affects a product developed by Sphinxsearch — matched by CVE ID, not by vendor name.