basicsecurity.net
Proof, not just disclosure.
Threats / Contributors / GitHub Security Advisories
Registry & coordination contributor

GitHub Security Advisories

cited as evidence in 485 · CNA assigner on 36 (independent) of 485 known-exploited records. Every aggregate on this page is recomputed from the records listed below — each one already cited to its public source.

github.com ↗ · home of the cited advisories

Independent CNA
485
records cited in
deterministic count
0
finder / reporter credits
CVE.org credits
36
CVE records catalogued (CNA)
independent
89%
avg modeled exploit prob.
FIRST EPSS, 485/485
29%
ransomware-associated
143 of 485 · CISA flag
R

Roles across the work

— find / fix / exploit / catalog, computed per record from credit type, the vendor-self-CNA gate, and the linked public exploit catalog
0
Find
record(s)
0
Fix
record(s)
0
Exploit
record(s)
36
Catalog
record(s)

Each dimension is a count of the listed records where this contributor did that job. A CNA row is fix only when the affected product is the assigner’s own; registries, coordinators, platforms, intel and research houses read as catalog, never fix. Exploit counts records where this contributor is credited as author of a public exploit / detection template in a linked catalog — we link the catalog, never host a payload.

01

Known for

— recomputed from this contributor’s own records
SurfacesApplication / other (276), Edge / remote-access infra (100), Server / web platform (86), Hypervisor / virtualization (17), Operating system / kernel (6)
WeaknessInjection (167), Path traversal / file (71), Authentication (71), Authorization / access control (47), Web / client (24)
PortfolioApache (35), Oracle (19), Ivanti (19), Synacor (15), VMware (15), Microsoft (14)
02

Narrative reach

— how far this contributor’s records carry an attacker, front door → lights out
1Front door
468reach this stage
2Keys to the kingdom
468reach this stage
3Lateral reach
450reach this stage
4Data at risk
80reach this stage
5Lights out
13reach this stage

Furthest any of these records carries an attacker: 5 · Lights out. 80 of 468 narrative-framed records reach data-at-risk or lights-out. (furthest-position idiom, reused from the landing map; the stage mapping is a model output over cited evidence.)

03

Recent highlights

— this contributor’s newest known-exploited records
04

Every record they’re cited in

— all 485, each linked to its cited source

This is the evidence behind every number above. Sorted ransomware-first, then by modeled exploit probability.

CVE-2024-23897Jenkins100%RWKEVCVE-2024-3400Palo Alto Networks100%RWKEVCVE-2024-21893Ivanti100%RWKEVCVE-2023-35082Ivanti100%RWKEVCVE-2024-21887Ivanti100%RWKEVCVE-2023-22518Atlassian100%RWKEVCVE-2023-35078Ivanti100%RWKEVCVE-2023-27350PaperCut100%RWKEVCVE-2023-0669Fortra100%RWKEVCVE-2022-26134Atlassian100%RWKEVCVE-2022-29464WSO2100%RWKEVCVE-2021-44228Apache100%RWKEVCVE-2021-40438Apache100%RWKEVCVE-2017-5638Apache100%RWKEVCVE-2018-13379Fortinet100%RWKEVCVE-2019-11510Ivanti100%RWKEVCVE-2019-19781Citrix100%RWKEVCVE-2020-5902F5100%RWKEVCVE-2021-21985VMware100%RWKEVCVE-2021-22005VMware100%RWKEVCVE-2021-26084Atlassian100%RWKEVCVE-2021-26855Microsoft100%RWKEVCVE-2021-34473Microsoft100%RWKEVCVE-2021-35464ForgeRock100%RWKEVCVE-2025-3248Langflow100%RWKEVCVE-2022-22954VMware100%RWKEVCVE-2017-10271Oracle100%RWKEVCVE-2018-7600Drupal100%RWKEVCVE-2021-41773Apache100%RWKEVCVE-2024-27199JetBrains100%RWKEVCVE-2023-29300Adobe100%RWKEVCVE-2024-4577PHP Group100%RWKEVCVE-2023-46805Ivanti100%RWKEVCVE-2023-22527Atlassian100%RWKEVCVE-2022-40684Fortinet100%RWKEVCVE-2025-53770Microsoft100%RWKEVCVE-2023-42793JetBrains100%RWKEVCVE-2024-24919Check Point100%RWKEVCVE-2021-45046Apache100%RWKEVCVE-2025-0282Ivanti100%RWKEVCVE-2022-47986IBM100%RWKEVCVE-2019-2725Oracle100%RWKEVCVE-2021-42013Apache100%RWKEVCVE-2025-5777Citrix100%RWKEVCVE-2024-1709ConnectWise100%RWKEVCVE-2022-1388F5100%RWKEVCVE-2023-38035Ivanti100%RWKEVCVE-2025-31161CrushFTP100%RWKEVCVE-2018-10562Dasan100%RWKEVCVE-2021-3129Laravel100%RWKEVCVE-2024-27198JetBrains100%RWKEVCVE-2021-26085Atlassian100%RWKEVCVE-2023-34362Progress100%RWKEVCVE-2019-3396Atlassian100%RWKEVCVE-2019-7481SonicWall100%RWKEVCVE-2021-20038SonicWall100%RWKEVCVE-2021-22986F5100%RWKEVCVE-2025-49706Microsoft100%RWKEVCVE-2020-0796Microsoft100%RWKEVCVE-2019-15107Webmin100%RWKEVCVE-2022-47966Zoho100%RWKEVCVE-2021-22205GitLab100%RWKEVCVE-2021-38647Microsoft100%RWKEVCVE-2025-61882Oracle100%RWKEVCVE-2010-2861Adobe100%RWKEVCVE-2023-3519Citrix100%RWKEVCVE-2024-0012Palo Alto Networks100%RWKEVCVE-2023-46604Apache100%RWKEVCVE-2023-29357Microsoft100%RWKEVCVE-2025-55182Meta100%RWKEVCVE-2025-10035Fortra100%RWKEVCVE-2017-12615Apache100%RWKEVCVE-2021-21972VMware100%RWKEVCVE-2025-31324SAP100%RWKEVCVE-2018-7602Drupal99%RWKEVCVE-2023-22515Atlassian99%RWKEVCVE-2021-44529Ivanti99%RWKEVCVE-2021-40539Zoho99%RWKEVCVE-2023-47246SysAid99%RWKEVCVE-2024-50623Cleo99%RWKEVCVE-2022-21587Oracle98%RWKEVCVE-2024-55591Fortinet98%RWKEVCVE-2024-41713Mitel98%RWKEVCVE-2026-41940WebPros98%RWKEVCVE-2021-42237Sitecore98%RWKEVCVE-2025-61884Oracle98%RWKEVCVE-2023-48788Fortinet98%RWKEVCVE-2019-5544VMware97%RWKEVCVE-2018-6530D-Link97%RWKEVCVE-2023-38203Adobe97%RWKEVCVE-2023-46747F597%RWKEVCVE-2026-23760SmarterTools96%RWKEVCVE-2018-1273VMware Tanzu96%RWKEVCVE-2026-35273Oracle95%RWKEVCVE-2019-11580Atlassian95%RWKEVCVE-2022-36537ZK Framework95%RWKEVCVE-2024-57727SimpleHelp 95%RWKEVCVE-2024-53704SonicWall95%RWKEVCVE-2024-51378CyberPersons95%RWKEVCVE-2017-9822DotNetNuke (DNN)95%RWKEVCVE-2024-9474Palo Alto Networks95%RWKEVCVE-2024-6670Progress95%RWKEVCVE-2026-0257Palo Alto Networks94%RWKEVCVE-2024-55956Cleo94%RWKEVCVE-2018-11138Quest92%RWKEVCVE-2021-35211SolarWinds91%RWKEVCVE-2022-26352dotCMS91%RWKEVCVE-2017-12149Red Hat91%RWKEVCVE-2024-40711Veeam90%RWKEVCVE-2023-40044Progress90%RWKEVCVE-2019-7195QNAP90%RWKEVCVE-2022-37042Synacor89%RWKEVCVE-2019-7192QNAP88%RWKEVCVE-2026-1731BeyondTrust88%RWKEVCVE-2022-27593QNAP88%RWKEVCVE-2026-24423SmarterTools88%RWKEVCVE-2019-16057D-Link87%RWKEVCVE-2024-51567CyberPersons87%RWKEVCVE-2017-18362Kaseya87%RWKEVCVE-2021-30116Kaseya86%RWKEVCVE-2020-3580Cisco86%RWKEVCVE-2025-52691SmarterTools85%RWKEVCVE-2022-27924Synacor85%RWKEVCVE-2023-41265Qlik84%RWKEVCVE-2022-24990TerraMaster84%RWKEVCVE-2021-20021SonicWall83%RWKEVCVE-2019-7194QNAP83%RWKEVCVE-2023-43208NextGen Healthcare83%RWKEVCVE-2026-50751Check Point83%RWKEVCVE-2023-41266Qlik82%RWKEVCVE-2026-15409SonicWall78%RWKEVCVE-2021-21975VMware78%RWKEVCVE-2021-28799QNAP78%RWKEVCVE-2023-27351PaperCut77%RWKEVCVE-2021-42258BQE73%RWKEVCVE-2021-27877Veritas65%RWKEVCVE-2024-55550Mitel38%RWKEVCVE-2022-24682Synacor31%RWKEVCVE-2019-13608Citrix30%RWKEVCVE-2018-6882Synacor25%RWKEVCVE-2020-2021Palo Alto Networks4%RWKEVCVE-2026-45321TanStack2%RWKEVCVE-2026-48027Nx2%RWKEVCVE-2021-26086Atlassian100%KEVCVE-2023-1671Sophos100%KEVCVE-2023-32315Ignite Realtime100%KEVCVE-2023-1389TP-Link100%KEVCVE-2017-9841PHPUnit100%KEVCVE-2015-1635Microsoft100%KEVCVE-2014-6271GNU100%KEVCVE-2021-1498Cisco100%KEVCVE-2017-7921Hikvision100%KEVCVE-2012-1823PHP100%KEVCVE-2013-2251Apache100%KEVCVE-2024-3273D-Link100%KEVCVE-2020-14882Oracle100%KEVCVE-2019-16920D-Link100%KEVCVE-2022-44877CWP100%KEVCVE-2020-8515DrayTek100%KEVCVE-2020-3452Cisco100%KEVCVE-2024-34102Adobe100%KEVCVE-2018-11776Apache100%KEVCVE-2017-12617Apache100%KEVCVE-2024-7593Ivanti100%KEVCVE-2020-9054Zyxel100%KEVCVE-2019-9670Synacor100%KEVCVE-2024-45195Apache100%KEVCVE-2021-20090Arcadyan100%KEVCVE-2024-4879ServiceNow100%KEVCVE-2020-25506D-Link100%KEVCVE-2024-38475Apache100%KEVCVE-2024-29824Ivanti100%KEVCVE-2018-15961Adobe100%KEVCVE-2025-24813Apache100%KEVCVE-2022-30525Zyxel100%KEVCVE-2020-10189Zoho100%KEVCVE-2022-35405Zoho100%KEVCVE-2022-22963VMware Tanzu100%KEVCVE-2021-39226Grafana Labs100%KEVCVE-2021-1497Cisco100%KEVCVE-2025-4427Ivanti100%KEVCVE-2015-1427Elastic100%KEVCVE-2018-0296Cisco100%KEVCVE-2026-10520Ivanti100%KEVCVE-2024-45519Synacor100%KEVCVE-2019-1653Cisco100%KEVCVE-2021-33044Dahua100%KEVCVE-2021-36260Hikvision100%KEVCVE-2021-44515Zoho100%KEVCVE-2025-24893XWiki100%KEVCVE-2021-35394Realtek100%KEVCVE-2025-59287Microsoft100%KEVCVE-2025-32432Craft CMS100%KEVCVE-2026-33017Langflow100%KEVCVE-2024-13159Ivanti100%KEVCVE-2023-23752Joomla!100%KEVCVE-2022-46169Cacti100%KEVCVE-2021-37415Zoho100%KEVCVE-2017-7269Microsoft100%KEVCVE-2023-21839Oracle100%KEVCVE-2022-1040Sophos100%KEVCVE-2024-36401OSGeo100%KEVCVE-2016-6277NETGEAR100%KEVCVE-2020-13927Apache100%KEVCVE-2023-38205Adobe100%KEVCVE-2020-7961Liferay100%KEVCVE-2023-29298Adobe100%KEVCVE-2020-15505Ivanti100%KEVCVE-2019-16759vBulletin100%KEVCVE-2016-10033PHP100%KEVCVE-2022-35914Teclib100%KEVCVE-2022-22965VMware100%KEVCVE-2024-5217ServiceNow100%KEVCVE-2025-48703CWP100%KEVCVE-2024-28995SolarWinds100%KEVCVE-2024-9465Palo Alto Networks100%KEVCVE-2020-16846SaltStack100%KEVCVE-2023-20198Cisco100%KEVCVE-2021-33045Dahua100%KEVCVE-2024-4040CrushFTP100%KEVCVE-2018-20062ThinkPHP100%KEVCVE-2018-0171Cisco100%KEVCVE-2024-23692Rejetto99%KEVCVE-2018-2628Oracle99%KEVCVE-2024-32113Apache99%KEVCVE-2023-34048VMware99%KEVCVE-2024-38856Apache99%KEVCVE-2017-9805Apache99%KEVCVE-2021-32030ASUS99%KEVCVE-2014-6287Rejetto99%KEVCVE-2024-4885Progress99%KEVCVE-2022-0543Redis99%KEVCVE-2020-1938Apache99%KEVCVE-2020-14750Oracle99%KEVCVE-2024-27348Apache99%KEVCVE-2026-48282Adobe99%KEVCVE-2020-11978Apache99%KEVCVE-2022-24086Adobe99%KEVCVE-2022-36804Atlassian99%KEVCVE-2020-10199Sonatype99%KEVCVE-2019-16278Nostromo99%KEVCVE-2020-0618Microsoft99%KEVCVE-2017-3881Cisco99%KEVCVE-2019-3929Crestron99%KEVCVE-2020-7247OpenBSD99%KEVCVE-2022-3236Sophos99%KEVCVE-2017-9791Apache99%KEVCVE-2022-24816OSGeo99%KEVCVE-2024-29059Microsoft99%KEVCVE-2024-8963Ivanti99%KEVCVE-2025-32433Erlang99%KEVCVE-2019-17558Apache99%KEVCVE-2024-50603Aviatrix99%KEVCVE-2016-3088Apache99%KEVCVE-2024-20767Adobe99%KEVCVE-2019-5418Rails99%KEVCVE-2024-9463Palo Alto Networks98%KEVCVE-2025-0108Palo Alto Networks98%KEVCVE-2026-63030WordPress98%KEVCVE-2017-15944Palo Alto Networks98%KEVCVE-2018-1000861Jenkins98%KEVCVE-2016-1555NETGEAR98%KEVCVE-2023-20887VMware98%KEVCVE-2020-6207SAP98%KEVCVE-2022-22947VMware98%KEVCVE-2022-26138Atlassian98%KEVCVE-2021-39144XStream98%KEVCVE-2024-12987DrayTek98%KEVCVE-2023-25717Ruckus Wireless98%KEVCVE-2022-29303SolarView98%KEVCVE-2024-3272D-Link98%KEVCVE-2021-35395Realtek98%KEVCVE-2022-22536SAP98%KEVCVE-2020-14883Oracle98%KEVCVE-2025-68613n8n98%KEVCVE-2023-25280D-Link98%KEVCVE-2020-17519Apache98%KEVCVE-2020-11738WordPress98%KEVCVE-2021-22054Omnissa98%KEVCVE-2020-25078D-Link98%KEVCVE-2025-49113Roundcube98%KEVCVE-2022-43769Hitachi Vantara98%KEVCVE-2025-34028Commvault98%KEVCVE-2015-7450IBM98%KEVCVE-2021-45382D-Link98%KEVCVE-2021-36380Sunhillo98%KEVCVE-2021-33766Microsoft98%KEVCVE-2024-4358Progress97%KEVCVE-2024-56145Craft CMS97%KEVCVE-2019-9082ThinkPHP97%KEVCVE-2007-3010Alcatel97%KEVCVE-2023-27524Apache97%KEVCVE-2023-26360Adobe97%KEVCVE-2020-1956Apache97%KEVCVE-2020-25213WordPress97%KEVCVE-2020-14864Oracle97%KEVCVE-2026-34197Apache97%KEVCVE-2021-41277Metabase97%KEVCVE-2019-3398Atlassian97%KEVCVE-2019-7256Nice97%KEVCVE-2025-20281Cisco97%KEVCVE-2023-52163Digiever97%KEVCVE-2025-54236Adobe97%KEVCVE-2021-22502Micro Focus97%KEVCVE-2025-25257Fortinet97%KEVCVE-2020-25223Sophos97%KEVCVE-2023-33246Apache97%KEVCVE-2026-39987Marimo97%KEVCVE-2017-17562Embedthis96%KEVCVE-2021-35587Oracle96%KEVCVE-2017-3506Oracle96%KEVCVE-2026-20253Splunk96%KEVCVE-2019-20085TVT96%KEVCVE-2019-10068Kentico96%KEVCVE-2022-24112Apache96%KEVCVE-2020-5847Unraid96%KEVCVE-2022-23131Zabbix96%KEVCVE-2020-17530Apache96%KEVCVE-2020-5410VMware Tanzu96%KEVCVE-2022-41352Synacor95%KEVCVE-2009-1151phpMyAdmin95%KEVCVE-2024-1212Progress95%KEVCVE-2025-54068Laravel95%KEVCVE-2025-47812Wing FTP Server95%KEVCVE-2019-7609Elastic95%KEVCVE-2025-4008Smartbedded95%KEVCVE-2020-2883Oracle95%KEVCVE-2020-6287SAP95%KEVCVE-2023-24489Citrix95%KEVCVE-2023-7028GitLab95%KEVCVE-2017-12637SAP95%KEVCVE-2020-14644Oracle94%KEVCVE-2024-48248NAKIVO94%KEVCVE-2023-36845Juniper94%KEVCVE-2019-12989Citrix94%KEVCVE-2017-1000486Primetek94%KEVCVE-2026-21643Fortinet94%KEVCVE-2025-30406Gladinet94%KEVCVE-2025-24016Wazuh94%KEVCVE-2018-14933NUUO94%KEVCVE-2021-44077Zoho94%KEVCVE-2024-28987SolarWinds93%KEVCVE-2020-2551Oracle93%KEVCVE-2022-33891Apache93%KEVCVE-2016-4437Apache93%KEVCVE-2021-40870Aviatrix93%KEVCVE-2022-24706Apache92%KEVCVE-2022-43939Hitachi Vantara92%KEVCVE-2017-5689Intel92%KEVCVE-2019-2616Oracle92%KEVCVE-2025-2747Kentico92%KEVCVE-2025-11371Gladinet92%KEVCVE-2024-20439Cisco92%KEVCVE-2019-6340Drupal92%KEVCVE-2020-10148SolarWinds92%KEVCVE-2024-7399Samsung92%KEVCVE-2020-8657EyesOfNetwork92%KEVCVE-2025-64446Fortinet92%KEVCVE-2024-5910Palo Alto Networks92%KEVCVE-2024-11680ProjectSend92%KEVCVE-2023-36844Juniper91%KEVCVE-2024-13160Ivanti91%KEVCVE-2021-21315Npm package91%KEVCVE-2025-12480Gladinet91%KEVCVE-2021-21311Adminer90%KEVCVE-2021-32648October CMS90%KEVCVE-2020-3952VMware90%KEVCVE-2023-41763Microsoft90%KEVCVE-2020-29583Zyxel90%KEVCVE-2020-17463Fuel CMS90%KEVCVE-2024-13161Ivanti90%KEVCVE-2025-5086Dassault Systèmes90%KEVCVE-2025-37164Hewlett Packard Enterprise (HPE)90%KEVCVE-2026-39808Fortinet90%KEVCVE-2025-29635D-Link90%KEVCVE-2026-42208BerriAI89%KEVCVE-2017-5521NETGEAR89%KEVCVE-2026-35616Fortinet89%KEVCVE-2021-43798Grafana Labs89%KEVCVE-2014-3120Elastic89%KEVCVE-2020-8193Citrix88%KEVCVE-2026-9082Drupal88%KEVCVE-2025-61757Oracle88%KEVCVE-2025-57819Sangoma88%KEVCVE-2026-48908JoomShaper88%KEVCVE-2021-21973VMware88%KEVCVE-2020-17496vBulletin88%KEVCVE-2022-26143Mitel87%KEVCVE-2026-34910Ubiquiti87%KEVCVE-2020-8644PlaySMS87%KEVCVE-2021-40655D-Link87%KEVCVE-2018-19410Paessler86%KEVCVE-2019-4716IBM86%KEVCVE-2018-6961VMware86%KEVCVE-2021-31755Tenda86%KEVCVE-2025-20362Cisco86%KEVCVE-2019-10758MongoDB85%KEVCVE-2024-58136Yiiframework85%KEVCVE-2022-23134Zabbix85%KEVCVE-2024-28986SolarWinds85%KEVCVE-2019-11581Atlassian85%KEVCVE-2025-64328Sangoma85%KEVCVE-2020-15415DrayTek85%KEVCVE-2023-38950ZKTeco85%KEVCVE-2026-3055Citrix84%KEVCVE-2020-12641Roundcube84%KEVCVE-2020-7796Synacor84%KEVCVE-2020-5722Grandstream84%KEVCVE-2023-28432MinIO84%KEVCVE-2019-9874Sitecore84%KEVCVE-2025-34291Langflow84%KEVCVE-2020-11023JQuery84%KEVCVE-2015-3035TP-Link84%KEVCVE-2025-40551SolarWinds84%KEVCVE-2019-0193Apache84%KEVCVE-2026-56290Joomlack83%KEVCVE-2025-34026Versa83%KEVCVE-2026-42271BerriAI83%KEVCVE-2025-14847MongoDB83%KEVCVE-2021-27561Yealink83%KEVCVE-2025-8110Gogs82%KEVCVE-2019-9621Synacor81%KEVCVE-2026-1603Ivanti81%KEVCVE-2023-22952SugarCRM80%KEVCVE-2020-10987Tenda80%KEVCVE-2024-42009Roundcube80%KEVCVE-2018-18809TIBCO79%KEVCVE-2021-22555Linux79%KEVCVE-2023-49103ownCloud78%KEVCVE-2023-34192Synacor77%KEVCVE-2019-7238Sonatype77%KEVCVE-2025-6204Dassault Systèmes76%KEVCVE-2026-56291Balbooa76%KEVCVE-2021-25298Nagios75%KEVCVE-2021-20123DrayTek74%KEVCVE-2018-15811DotNetNuke (DNN)74%KEVCVE-2018-18325DotNetNuke (DNN)74%KEVCVE-2024-37383Roundcube73%KEVCVE-2019-9978WordPress73%KEVCVE-2018-7841Schneider Electric73%KEVCVE-2025-30066tj-actions72%KEVCVE-2025-40536SolarWinds72%KEVCVE-2021-25296Nagios72%KEVCVE-2026-16232Check Point71%KEVCVE-2025-6205Dassault Systèmes71%KEVCVE-2020-36193PEAR71%KEVCVE-2020-4427IBM70%KEVCVE-2021-20124DrayTek69%KEVCVE-2025-58360OSGeo65%KEVCVE-2025-2776SysAid64%KEVCVE-2025-11953React Native Community62%KEVCVE-2026-33634Aquasecurity59%KEVCVE-2025-31125Vite59%KEVCVE-2025-47813Wing FTP Server59%KEVCVE-2025-2746Kentico58%KEVCVE-2023-6549Citrix58%KEVCVE-2020-26919NETGEAR58%KEVCVE-2021-25297Nagios56%KEVCVE-2026-0770Langflow56%KEVCVE-2026-48907Widget Factory56%KEVCVE-2021-22175GitLab53%KEVCVE-2023-45249Acronis53%KEVCVE-2025-14611Gladinet51%KEVCVE-2021-22017VMware49%KEVCVE-2021-26829OpenPLC48%KEVCVE-2023-37580Synacor47%KEVCVE-2025-2775SysAid42%KEVCVE-2021-26828OpenPLC39%KEVCVE-2025-68645Synacor32%KEVCVE-2026-55255Langflow29%KEVCVE-2025-4632Samsung24%KEVCVE-2024-27443Synacor24%KEVCVE-2025-68461Roundcube20%KEVCVE-2019-5591Fortinet19%KEVCVE-2022-27926Synacor18%KEVCVE-2024-6047GeoVision10%KEVCVE-2023-28434MinIO7%KEVCVE-2018-0161Cisco5%KEVCVE-2025-23209Craft CMS4%KEVCVE-2025-27915Synacor4%KEVCVE-2025-54313Prettier4%KEVCVE-2025-48384Git3%KEVCVE-2025-30154reviewdog2%KEVCVE-2025-22226VMware2%KEVCVE-2025-35939Craft CMS1%KEV
05

Coverage & confidence

— what this profile claims, and what it does not

Established (cited)

  • Cited in 485 known-exploited records — the list below; every one links to its public source.
  • Catalogued 36 CVE record(s) as the CNA assigner (from CVE.org).
  • Coverage gaps — stated, not hidden

  • This profile is an aggregation: it asserts only what the listed records already cite — no new external claim about the contributor is made.
  • The TYPE badge and the narrative-stage mapping are editorial (our call), labeled as such, not a sourced fact.