Products › Server applications and development
Server applications and development
ERP, business applications and databases
ERP and CRM suites, business applications, business intelligence tools and databases.
For example: SAP NetWeaver, Oracle E-Business Suite, Metabase, SQL Server.
-
13 vulnerabilities added in the last 12 months
-
74 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 4, 2025 to Oct 3, 2025 | 2 |
| Oct 4, 2025 to Nov 2, 2025 | 4 |
| Nov 3, 2025 to Dec 2, 2025 | 0 |
| Dec 3, 2025 to Jan 1, 2026 | 2 |
| Jan 2, 2026 to Jan 31, 2026 | 0 |
| Feb 1, 2026 to Mar 2, 2026 | 0 |
| Mar 3, 2026 to Apr 1, 2026 | 0 |
| Apr 2, 2026 to May 1, 2026 | 1 |
| May 2, 2026 to May 31, 2026 | 0 |
| Jun 1, 2026 to Jun 30, 2026 | 2 |
| Jul 1, 2026 to Jul 30, 2026 | 1 |
| Jul 31, 2026 to Aug 29, 2026 | 2 |
| Aug 30, 2026 to Sep 28, 2026 (in progress) | 0 |
Affected brands
In alphabetical order, with their number of vulnerabilities in this category.
- Acclaim Systems 1 vulnerability
- Adminer 1 vulnerability · 1 in the last 12 months
- Advantive 2 vulnerabilities
- Apache 11 vulnerabilities
- BQE 1 vulnerability
- Checkbox 1 vulnerability
- Dassault Systèmes 3 vulnerabilities · 2 in the last 12 months
- Elastic 3 vulnerabilities
- Hitachi Vantara 2 vulnerabilities
- IBM 2 vulnerabilities
- Justice AV Solutions (JAVS) 1 vulnerability
- Metabase 2 vulnerabilities · 1 in the last 12 months
- Microsoft 2 vulnerabilities · 1 in the last 12 months
- MongoDB 2 vulnerabilities · 1 in the last 12 months
- NextGen Healthcare 1 vulnerability
- Novi Survey 1 vulnerability
- Oracle 9 vulnerabilities · 4 in the last 12 months
- OSGeo 3 vulnerabilities · 1 in the last 12 months
- phpMyAdmin 1 vulnerability
- Progress 1 vulnerability
- PTC 1 vulnerability · 1 in the last 12 months
- Qlik 3 vulnerabilities
- Redis 1 vulnerability
- Samsung 2 vulnerabilities · 1 in the last 12 months
- SAP 13 vulnerabilities
- SugarCRM 1 vulnerability
- TIBCO 2 vulnerabilities
- Trimble 1 vulnerability
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
See also
- Web and application servers 67 vulnerabilities
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.
Rank 1Metabase
CVE-2026-72898Active CERT-FR alertHunt for compromise (CISA)
Metabase SQL Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Aug 11, 2026
- CISA deadline
- 3 days
- CVSS severity
- 10.0 (critical)
Rank 2Oracle E-Business Suite
CVE-2026-46817Hunt for compromise (CISA)
Oracle E-Business Suite Improper Privilege Management Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jul 15, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 3PTC Windchill and FlexPLM
CVE-2026-12569Ransomware
PTC Windchill and FlexPLM Improper Input Validation Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jun 25, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 4Oracle PeopleSoft
CVE-2026-35273Ransomware
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jun 12, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 5Samsung MagicINFO Server
CVE-2024-7399CVE from 2024, added in 2026
Samsung MagicINFO 9 Server Path Traversal Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Apr 24, 2026
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 6OSGeo GeoServer
CVE-2025-58360OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Dec 11, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 7Oracle E-Business Suite
CVE-2025-61882Ransomware
Oracle E-Business Suite Unspecified Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Oct 6, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 8Dassault Systèmes DELMIA Apriso
CVE-2025-6205Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Oct 28, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.1 (critical)
Rank 9Microsoft SQL Server
CVE-2019-1068Hunt for compromise (CISA)CVE from 2019, added in 2026
Microsoft SQL Server Remote Code Execution Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Aug 26, 2026
- CISA deadline
- 3 days
- CVSS severity
- 8.8 (high)
Rank 10Dassault Systèmes DELMIA Apriso
CVE-2025-6204Dassault Systèmes DELMIA Apriso Code Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Oct 28, 2025
- CISA deadline
- 21 days
- CVSS severity
- 8.0 (high)
Show 62 more vulnerabilities
Rank 11MongoDB Server
CVE-2025-14847MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Dec 29, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 12Oracle E-Business Suite
CVE-2025-61884Ransomware
Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Oct 20, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 13Adminer
CVE-2021-21311CVE from 2021, added in 2025
Adminer Server-Side Request Forgery Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Sep 29, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Rank 14OSGeo GeoServer
CVE-2022-24816CVE from 2022, added in 2024
OSGeo GeoServer JAI-EXT Code Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 26, 2024
- CISA deadline
- 21 days
- CVSS severity
- 10.0 (critical)
Rank 15SAP NetWeaver
CVE-2022-22536SAP Multiple Products HTTP Request Smuggling Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 18, 2022
- CISA deadline
- 21 days
- CVSS severity
- 10.0 (critical)
Rank 16Redis Server
CVE-2022-0543Debian-specific Redis Server Lua Sandbox Escape Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 28, 2022
- CISA deadline
- 21 days
- CVSS severity
- 10.0 (critical)
Rank 17Elastic Kibana
CVE-2019-7609CVE from 2019, added in 2022
Kibana Arbitrary Code Execution
Added more than a year ago: ranked by severity.
- Added
- Jan 10, 2022
- CISA deadline
- 181 days
- CVSS severity
- 10.0 (critical)
Rank 18SAP NetWeaver
CVE-2010-5326CVE from 2010, added in 2021
SAP NetWeaver Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 10.0 (critical)
Rank 19SAP NetWeaver
CVE-2020-6287SAP NetWeaver Missing Authentication for Critical Function Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 10.0 (critical)
Rank 20Qlik Sense
CVE-2023-48365RansomwareCVE from 2023, added in 2025
Qlik Sense HTTP Tunneling Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 13, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.9 (critical)
Rank 21Qlik Sense
CVE-2023-41265Ransomware
Qlik Sense HTTP Tunneling Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 7, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.9 (critical)
Rank 22MongoDB mongo-express
CVE-2019-10758CVE from 2019, added in 2021
MongoDB mongo-express Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 10, 2021
- CISA deadline
- 182 days
- CVSS severity
- 9.9 (critical)
Rank 23Samsung MagicINFO Server
CVE-2025-4632Samsung MagicINFO 9 Server Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 22, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 24SAP NetWeaver
CVE-2025-31324Ransomware
SAP NetWeaver Unrestricted File Upload Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 29, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 25Hitachi Vantara Pentaho Business Analytics (BA) Server
CVE-2022-43939CVE from 2022, added in 2025
Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 26Apache HugeGraph
CVE-2024-27348Apache HugeGraph-Server Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 18, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 27Apache OFBiz
CVE-2024-38856Apache OFBiz Incorrect Authorization Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 27, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 28Apache OFBiz
CVE-2024-32113Apache OFBiz Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 7, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 29OSGeo GeoServer
CVE-2024-36401OSGeo GeoServer GeoTools Eval Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 15, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 30Progress Telerik Report Server
CVE-2024-4358Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 13, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 31NextGen Healthcare Mirth Connect
CVE-2023-43208Ransomware
NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 20, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 32Apache Superset
CVE-2023-27524Apache Superset Insecure Default Initialization of Resource Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 8, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 33Novi Survey
CVE-2023-29492Novi Survey Insecure Deserialization Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 13, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 34Oracle E-Business Suite
CVE-2022-21587Ransomware
Oracle E-Business Suite Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 2, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 35Apache CouchDB
CVE-2022-24706Apache CouchDB Insecure Default Initialization of Resource Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 36SAP NetWeaver
CVE-2016-2386CVE from 2016, added in 2022
SAP NetWeaver SQL Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 9, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 37phpMyAdmin
CVE-2009-1151CVE from 2009, added in 2022
phpMyAdmin Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 38Elastic Elasticsearch
CVE-2015-1427CVE from 2015, added in 2022
Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 39IBM Planning Analytics (TM1)
CVE-2019-4716CVE from 2019, added in 2021
IBM Planning Analytics Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 40SAP Solution Manager
CVE-2020-6207SAP Solution Manager Missing Authentication for Critical Function Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 41BQE BillQuick Web Suite
CVE-2021-42258Ransomware
BQE BillQuick Web Suite SQL Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 42SAP NetWeaver
CVE-2025-42999Ransomware
SAP NetWeaver Deserialization Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 15, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.1 (critical)
Rank 43Dassault Systèmes DELMIA Apriso
CVE-2025-5086Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 11, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.0 (critical)
Rank 44Advantive VeraCore
CVE-2024-57968Advantive VeraCore Unrestricted File Upload Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 10, 2025
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 45Oracle Agile PLM
CVE-2024-20953Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 24, 2025
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 46Trimble Cityworks
CVE-2025-0994Trimble Cityworks Deserialization Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 7, 2025
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 47Microsoft SQL Server
CVE-2020-0618RansomwareCVE from 2020, added in 2024
Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 18, 2024
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 48Apache Spark
CVE-2022-33891Apache Spark Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 7, 2023
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 49SugarCRM Sugar (Sell, Serve, Enterprise)
CVE-2023-22952Multiple SugarCRM Products Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 2, 2023
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 50TIBCO JasperReports
CVE-2018-5430CVE from 2018, added in 2022
TIBCO JasperReports Server Information Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 29, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 51SAP NetWeaver
CVE-2021-38163SAP NetWeaver Unrestricted File Upload Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 9, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 52Apache Kylin
CVE-2020-1956CVE from 2020, added in 2022
Apache Kylin OS Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 53Justice AV Solutions (JAVS) JAVS Viewer
CVE-2024-4978Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 29, 2024
- CISA deadline
- 21 days
- CVSS severity
- 8.4 (high)
Rank 54Acclaim Systems USAHERDS
CVE-2021-44207CVE from 2021, added in 2024
Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 23, 2024
- CISA deadline
- 21 days
- CVSS severity
- 8.1 (high)
Rank 55Elastic Elasticsearch
CVE-2014-3120CVE from 2014, added in 2022
Elasticsearch Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.1 (high)
Rank 56SAP NetWeaver
CVE-2017-12637CVE from 2017, added in 2025
SAP NetWeaver Directory Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 19, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 57Advantive VeraCore
CVE-2025-25181Advantive VeraCore SQL Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 10, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 58Apache OFBiz
CVE-2024-45195Apache OFBiz Forced Browsing Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 4, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 59Oracle Agile PLM
CVE-2024-21287Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 21, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 60Metabase
CVE-2021-41277CVE from 2021, added in 2024
Metabase GeoJSON API Local File Inclusion Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 12, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 61Apache Flink
CVE-2020-17519CVE from 2020, added in 2024
Apache Flink Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 23, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 62Oracle Business Intelligence (OBIEE / BI Publisher)
CVE-2020-14864CVE from 2020, added in 2022
Oracle Business Intelligence Enterprise Edition Path Transversal
Added more than a year ago: ranked by severity.
- Added
- Jan 18, 2022
- CISA deadline
- 181 days
- CVSS severity
- 7.5 (high)
Rank 63SAP NetWeaver
CVE-2016-3976CVE from 2016, added in 2021
SAP NetWeaver Directory Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.5 (high)
Rank 64Apache Solr
CVE-2019-17558CVE from 2019, added in 2021
Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.5 (high)
Rank 65Hitachi Vantara Pentaho Business Analytics (BA) Server
CVE-2022-43769CVE from 2022, added in 2025
Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Rank 66Oracle Business Intelligence (OBIEE / BI Publisher)
CVE-2019-2616CVE from 2019, added in 2022
Oracle BI Publisher Unauthorized Access Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Rank 67Apache Solr
CVE-2019-0193CVE from 2019, added in 2021
Apache Solr DataImportHandler Code Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 10, 2021
- CISA deadline
- 182 days
- CVSS severity
- 7.2 (high)
Rank 68SAP CRM
CVE-2018-2380RansomwareCVE from 2018, added in 2021
SAP Customer Relationship Management (CRM) Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 6.6 (medium)
Rank 69Qlik Sense
CVE-2023-41266Ransomware
Qlik Sense Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 7, 2023
- CISA deadline
- 21 days
- CVSS severity
- 6.5 (medium)
Rank 70TIBCO JasperReports
CVE-2018-18809CVE from 2018, added in 2022
TIBCO JasperReports Library Directory Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 29, 2022
- CISA deadline
- 21 days
- CVSS severity
- 6.5 (medium)
Rank 71SAP NetWeaver
CVE-2016-9563CVE from 2016, added in 2021
SAP NetWeaver XML External Entity (XXE) Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 6.5 (medium)
Rank 72SAP NetWeaver
CVE-2016-2388CVE from 2016, added in 2022
SAP NetWeaver Information Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 9, 2022
- CISA deadline
- 21 days
- CVSS severity
- 5.3 (medium)
End of life: remove
These products are no longer supported: no patch is coming. Remove them or isolate them from the network.
IBM InfoSphere BigInsights
CVE-2013-3993RansomwareEnd of lifeCVE from 2013, added in 2022
IBM InfoSphere BigInsights Invalid Input Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- May 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 6.5 (medium)
Checkbox Survey
CVE-2021-27852End of life
Checkbox Survey Deserialization of Untrusted Data Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Apr 11, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Follow and verify
Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.