Universal Forwarder
Vendor:
First CVE: Feb 14, 2020 · Active for 6 years
61
Total CVEs
More Total CVEs than 98% of tracked products
12.2
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Universal Forwarder over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 14, 2020
6 years ago
Most Recent CVE
Jun 2, 2025
417 days ago
CVE Severity & Scoring
Universal Forwarder61 CVEs
8%
39%
43%
10%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (6.6%)
Network57 (93.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low46 (75.4%)
High15 (24.6%)
Unknown0 (0.0%)
User Interaction
None46 (75.4%)
Unknown0 (0.0%)
Required15 (24.6%)
Privileges Required
Low8 (13.1%)
High0 (0.0%)
None53 (86.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (61 CVEs).
61 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-22901HIGH curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malic | Jun 11, 2021 | 8.1 | 60 | NO | NO |
CVE-2021-30560HIGH Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Aug 3, 2021 | 8.8 | 39 | NO | NO |
CVE-2022-32206MEDIUM curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number o | Jul 7, 2022 | 6.5 | 38 | NO | NO |
CVE-2022-32221CRITICAL When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been s | Dec 5, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-36227CRITICAL In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resul | Nov 22, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-35737HIGH SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API. | Aug 3, 2022 | 7.5 | 32 | NO | NO |
CVE-2021-22945CRITICAL When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in | Sep 23, 2021 | 9.1 | 32 | NO | NO |
CVE-2021-3520CRITICAL There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a neg | Jun 2, 2021 | 9.8 | 32 | NO | NO |
CVE-2022-32205MEDIUM A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookie | Jul 7, 2022 | 4.3 | 31 | NO | NO |
CVE-2023-27533HIGH A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet op | Mar 30, 2023 | 8.8 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (61 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (61 CVEs).
Media Mentions
Signals from CVEs in this product scope (61 CVEs).
Top CNAs Publishing CVEs For Universal Forwarder
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.1.0 | 58 | 6.8 | 5.9% | 0 | 0 |