Super Xray Project maintains a focused X-ray analysis tool whose vulnerability exposure centers on deserialization flaws and improper privilege-execution patterns within the core product. These weakness classes reflect the challenges inherent to secure handling of untrusted input and access control in utility-level software; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Super Xray Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-41945CRITICAL super-xray is a vulnerability scanner (xray) GUI launcher. In version 0.1-beta, the URL is not filtered and directly spliced into the command, resulting in a possible RCE vulnera | Nov 21, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-41950HIGH super-xray is the GUI alternative for vulnerability scanning tool xray. In 0.2-beta, a privilege escalation vulnerability was discovered. This caused inaccurate default xray permis | Nov 22, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-41958HIGH super-xray is a web vulnerability scanning tool. Versions prior to 0.7 assumed trusted input for the program config which is stored in a yaml file. An attacker with local access to | Nov 25, 2022 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Super Xray Project.
Media articles that mention a CVE ID that affects a product developed by Super Xray Project — matched by CVE ID, not by vendor name.