Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Thycotic

First CVE: Jun 2, 2015Active for: 11 yearsTotal CVEs: 9

Thycotic develops credential management and secrets-handling products such as Secret Server and Password Reset Server that occupy a critical position in enterprise identity and access infrastructure. The vendor's vulnerability profile skews toward serious outcomes and frequently acquires public exploit code, with recurring exposure centered on web-application input handling and validation defects including cross-site scripting, SQL injection, server-side request forgery, and improper certificate validation. Defenders should prioritize patching this vendor's offerings given their role in controlling access to high-value assets; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Thycotic over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 2, 2015
11 years ago
Most Recent CVE
Oct 1, 2021
1,758 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-18355CRITICAL
An SSRF issue was discovered in the legacy Web launcher in Thycotic Secret Server before 10.7.
Oct 23, 20199.827NONO
CVE-2014-4861CRITICAL
The Remote Desktop Launcher in Thycotic Secret Server before 8.6.000010 does not properly cleanup a temporary file that contains an encrypted password once a session has ended.
Mar 9, 20189.824NONO
CVE-2021-34679HIGH
Thycotic Password Reset Server before 5.3.0 allows credential disclosure.
Jun 11, 20217.523NONO
CVE-2021-41845MEDIUM
A SQL injection issue was discovered in ThycoticCentrify Secret Server before 11.0.000007. The only affected versions are 10.9.000032 through 11.0.000006.
Oct 1, 20216.522NONO
CVE-2019-18357MEDIUM
An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 2 of 2).
Oct 23, 20196.121NONO
CVE-2019-18356MEDIUM
An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 1 of 2).
Oct 23, 20196.121NONO
CVE-2015-3443LOW
Cross-site scripting (XSS) vulnerability in the basic dashboard in Thycotic Secret Server 8.6.x, 8.7.x, and 8.8.x before 8.8.000005 allows remote authenticated users to inject arbi
Jul 2, 20153.520NOYES
CVE-2015-4094MEDIUM
The Thycotic Password Manager Secret Server application through 2.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof s
Jun 2, 20155.816NONO
CVE-2017-11725MEDIUM
The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections.
Jul 29, 20175.415NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
11%
56%
11%
22%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (77.8%)
Unknown2 (22.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (77.8%)
High0 (0.0%)
Unknown2 (22.2%)
User Interaction
None4 (44.4%)
Unknown2 (22.2%)
Required3 (33.3%)
Privileges Required
Low2 (22.2%)
High0 (0.0%)
None5 (55.6%)
Unknown2 (22.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
11.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Thycotic.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Thycotic — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Thycotic's Products

View all 2 CNAs →

Top CWEs