- How many CVEs does XStream have?
- XStream has 38 published CVE records since 2016, including 0 in the last two years.
- How many XStream CVEs are in CISA KEV?
- Yes — 1 of XStream's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
- Which XStream products have the most CVEs?
- The XStream products with the most published CVEs are xstream, com.thoughtworks.xstream:xstream, Woodstox, x-stream.
- What are the most common weakness types in XStream CVEs?
- XStream's CVEs most often map to these CWE weakness types: CWE-502 (Deserialization of Untrusted Data), CWE-121 (Stack-based Buffer Overflow), CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')), CWE-434 (Unrestricted Upload of File with Dangerous Type).
- Are there public exploits for XStream vulnerabilities?
- Yes — 14 of XStream's CVEs have a known public exploit.
- How many critical XStream vulnerabilities are there?
- XStream has 10 critical and 26 high-severity CVEs.
- What is the average severity of XStream CVEs?
- The average CVSS base score across XStream's scored CVEs is 8.5.