Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Squaredup

First CVE: Feb 3, 2021Active for: 5 yearsTotal CVEs: 13
8.6
VTI Score
Low

Squaredup develops monitoring and visualization dashboards for enterprise infrastructure platforms, particularly for System Center Operations Manager (SCOM) environments, positioning itself at the nexus of operational visibility and web-facing administration interfaces. Its vulnerability profile centers on application-layer input-handling weaknesses—cross-site scripting, cross-site request forgery, and server-side request forgery—that are characteristic of web-based management tools, with a meaningful share reaching serious severity. Defenders should prioritize patching this vendor's releases in environments where dashboards are internet-exposed or accessible to untrusted networks; current severity and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Squaredup over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 3, 2021
5 years ago
Most Recent CVE
Sep 3, 2024
689 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-40091CRITICAL
An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654.
Dec 6, 20219.830NONO
CVE-2022-46785MEDIUM
SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 1 of 2).
Feb 23, 20236.122NONO
CVE-2020-9388MEDIUM
CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via
Feb 3, 20216.522NONO
CVE-2022-46784MEDIUM
SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows open redirection. (The issue was originally found in 5.5.1 GA.)
Feb 23, 20236.121NONO
CVE-2021-40094MEDIUM
A DOM-based XSS vulnerability affects SquaredUp for SCOM 5.2.1.6654. If successfully exploited, this vulnerability may allow attackers to inject malicious code into a user's device
Dec 7, 20215.420NONO
CVE-2021-40092MEDIUM
A cross-site scripting (XSS) vulnerability in Image Tile in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via an SVG file.
Dec 7, 20215.420NONO
CVE-2020-9390MEDIUM
SquaredUp allowed Stored XSS before version 4.6.0. A user was able to create a dashboard that executed malicious content in iframe or by uploading an SVG that contained a script.
Feb 3, 20215.420NONO
CVE-2021-40096MEDIUM
A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via modifica
Dec 7, 20215.419NONO
CVE-2021-40093MEDIUM
A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via dashboar
Dec 7, 20215.419NONO
CVE-2024-45180MEDIUM
SquaredUp DS for SCOM 6.2.1.11104 allows XSS.
Sep 3, 20245.417NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
85%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (92.3%)
High1 (7.7%)
Unknown0 (0.0%)
User Interaction
None3 (23.1%)
Unknown0 (0.0%)
Required10 (76.9%)
Privileges Required
Low7 (53.8%)
High1 (7.7%)
None5 (38.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Squaredup.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Squaredup — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Squaredup's Products

View all 1 CNAs →

Top CWEs