Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Status2k

First CVE: Aug 6, 2014Active for: 12 yearsTotal CVEs: 7

Status2k is a modestly represented vendor with a narrow product portfolio centered on a single application, yet its vulnerabilities skew strongly toward critical-severity outcomes and frequently acquire public exploit code. The recurring weakness classes—including improper input validation, sensitive-information exposure, code injection, cross-site scripting, and SQL injection—reflect the application-layer and data-handling risks endemic to web-facing software. Defenders should prioritize patching this vendor's disclosures despite its limited scope, given the severity tendency and exploit availability; live exploitation activity and current exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
3.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Status2k over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2014
11 years ago
Most Recent CVE
Feb 7, 2020
2,359 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-5091CRITICAL
A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious user execute arbitrary PHP code.
Feb 7, 20209.849NOYES
CVE-2014-5093CRITICAL
Status2k does not remove the install directory allowing credential reset.
Jan 10, 20209.843NOYES
CVE-2014-5092HIGH
Status2k allows Remote Command Execution in admin/options/editpl.php.
Jan 10, 20208.839NOYES
CVE-2014-5089HIGH
SQL injection vulnerability in admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary SQL commands via the log parameter.
Aug 6, 20147.533NOYES
CVE-2014-5090MEDIUM
admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the Location field in Add Logs in the Admin
Aug 6, 20146.531NOYES
CVE-2014-5094MEDIUM
Status2k allows remote attackers to obtain configuration information via a phpinfo action in a request to status/index.php, which calls the phpinfo function.
Oct 20, 20145.028NOYES
CVE-2014-5088MEDIUM
Cross-site scripting (XSS) vulnerability in Status2k allows remote attackers to inject arbitrary web script or HTML via the username to login.php.
Aug 6, 20144.325NOYES
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
43%
29%
29%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (42.9%)
Unknown4 (57.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (42.9%)
High0 (0.0%)
Unknown4 (57.1%)
User Interaction
None3 (42.9%)
Unknown4 (57.1%)
Required0 (0.0%)
Privileges Required
Low1 (14.3%)
High0 (0.0%)
None2 (28.6%)
Unknown4 (57.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
100.0% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Status2k.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Status2k — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Status2k's Products

View all 1 CNAs →

Top CWEs