- How many CVEs does aquasecurity have?
- aquasecurity has 7 published CVE records since 2024, including 6 in the last two years.
- How many aquasecurity CVEs are in CISA KEV?
- Yes — 1 of aquasecurity's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
- Which aquasecurity products have the most CVEs?
- The aquasecurity products with the most published CVEs are trivy, github.com/aquasecurity/trivy, trivy-action, aquasecurity/trivy-action, setup-trivy.
- What are the most common weakness types in aquasecurity CVEs?
- aquasecurity's CVEs most often map to these CWE weakness types: CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')), CWE-506 (Embedded Malicious Code), CWE-522 (Insufficiently Protected Credentials), CWE-770 (Allocation of Resources Without Limits or Throttling).
- Are there public exploits for aquasecurity vulnerabilities?
- Yes — 2 of aquasecurity's CVEs have a known public exploit.
- How many critical aquasecurity vulnerabilities are there?
- aquasecurity has 2 critical and 3 high-severity CVEs.
- What is the average severity of aquasecurity CVEs?
- The average CVSS base score across aquasecurity's scored CVEs is 7.9.