Xerosecurity maintains a focused security assessment and reconnaissance tool portfolio centered on the Sn1per product, which performs network enumeration and vulnerability scanning across enterprise infrastructure. The recurring vulnerability signal centers on improper default permissions, reflecting the exposure inherent in assessment and scanning tools that require broad access to network resources and systems. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xerosecurity over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-39274CRITICAL In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing an unprivileged user to modify the main application and the a | Aug 19, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-39273HIGH In XeroSecurity Sn1per 9.0 (free version), insecure permissions (0777) are set upon application execution, allowing an unprivileged user to modify the application, modules, and con | Aug 19, 2021 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xerosecurity.
Media articles that mention a CVE ID that affects a product developed by Xerosecurity — matched by CVE ID, not by vendor name.