Universal Forwarder

Vendor:

First CVE: Feb 14, 2020 · Active for 6 years

61
Total CVEs
More Total CVEs than 98% of tracked products
12.2
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Universal Forwarder over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 14, 2020
6 years ago
Most Recent CVE
Jun 2, 2025
417 days ago

CVE Severity & Scoring

Universal Forwarder61 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local4 (6.6%)
Network57 (93.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low46 (75.4%)
High15 (24.6%)
Unknown0 (0.0%)
User Interaction
None46 (75.4%)
Unknown0 (0.0%)
Required15 (24.6%)
Privileges Required
Low8 (13.1%)
High0 (0.0%)
None53 (86.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (61 CVEs).

61 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malic
Jun 11, 20218.160NONO
Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Aug 3, 20218.839NONO
curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number o
Jul 7, 20226.538NONO
When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been s
Dec 5, 20229.832NONO
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resul
Nov 22, 20229.832NONO
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.
Aug 3, 20227.532NONO
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in
Sep 23, 20219.132NONO
There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a neg
Jun 2, 20219.832NONO
A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookie
Jul 7, 20224.331NONO
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet op
Mar 30, 20238.829NONO

Exploit Exposure

Signals from CVEs in this product scope (61 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (61 CVEs).

Media Mentions

Signals from CVEs in this product scope (61 CVEs).

Top CNAs Publishing CVEs For Universal Forwarder

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.1.0586.85.9%00