Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Surfcontrol

First CVE: Feb 3, 2000Active for: 26 yearsTotal CVEs: 12
29.6
VTI Score
Low

Surfcontrol's vulnerability profile centers on web and email filtering appliances designed for enterprise content control and security policy enforcement. The recurring disclosures affecting its SuperScout product line frequently acquire public exploit code, reflecting the appeal of gateway filtering systems as targets for bypass research and access escalation. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
5.3
Avg CVSS Score
Higher Avg CVSS Score than 15% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Surfcontrol over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 3, 2000
26 years ago
Most Recent CVE
Mar 31, 2003
8,516 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2002-0709HIGH
SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to execute arbitrary SQL queries via the RunReport option to Sim
Oct 10, 20027.528NOYES
CVE-2002-0708MEDIUM
Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to read arbitrary files via an HTTP request containing ...
Oct 10, 20025.025NOYES
CVE-2002-1530MEDIUM
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and plaintext passwords via a request to the userlist.asp progr
Mar 31, 20035.024NOYES
CVE-2002-1529MEDIUM
Cross-site scripting (XSS) vulnerability in msgError.asp for the administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to insert a
Mar 31, 20034.322NOYES
CVE-2002-0705HIGH
The Web Reports Server for SurfControl SuperScout WebFilter stores the "scwebusers" username and password file in a web-accessible directory, which allows remote attackers to obtai
Oct 10, 20027.520NONO
CVE-2002-2121MEDIUM
SurfControl SuperScout Email filter for SMTP 3.5.1 allows remote attackers to cause a denial of service (crash) via a long SMTP (1) HELO or (2) RCPT TO command, possibly due to a b
Dec 31, 20025.019NONO
CVE-2002-0706HIGH
UserManager.js in the Web Reports Server for SurfControl SuperScout WebFilter uses weak encryption for administrator functions, which allows remote attackers to decrypt the adminis
Oct 10, 20027.519NONO
CVE-2002-1531MEDIUM
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (crash) via an HTTP request without a Conte
Mar 31, 20035.015NONO
CVE-2002-1532MEDIUM
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (resource exhaustion) via a GET request wit
Mar 31, 20035.015NONO
CVE-2002-0707MEDIUM
The Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to cause a denial of service (CPU consumption) via large GET requests, possibly due to a buffer
Oct 10, 20025.015NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
8%
67%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown12 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown12 (100.0%)
User Interaction
None0 (0.0%)
Unknown12 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown12 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
33.3% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Surfcontrol.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Surfcontrol — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Surfcontrol's Products

View all 1 CNAs →