CVE Tools

Barry-warsaw

4 CVEs tracked since 2016. Since Sep 2016, none of them reached CISA KEV.

Barry-warsaw CVEs per month

Sep 2016 to Nov 2021. Point at a month, or focus the strip and use the arrow keys.
Barry-warsaw CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2016-0920
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-1120

Products

The products that kept showing up in Barry-warsaw's monthly top three, with their CVEs summed over those months.

  1. Gnu Mailman42 months

Latest CVEs

The 9 most recently published vulnerabilities affecting Barry-warsaw.

  1. CVE-2025-43921GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple third parties report that they are unable to re...5.3
  2. CVE-2025-43919GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authent...5.8
  3. CVE-2021-44227In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.8.8
  4. CVE-2021-43332In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an of...6.5
  5. CVE-2021-43331In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS.6.1
  6. CVE-2020-15011GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page.4.3
  7. CVE-2020-12137GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP re...6.1
  8. CVE-2016-7123Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators.8.8
  9. CVE-2016-6893Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2.1.x before 2.1.23 allows remote attackers to hijack the authentication of arbitrary users for requests that...8.8

The record

Peak rank
#53 in Sep 2016
Busiest month shown
Sep 2016, 2 CVEs
Months with a KEV entry
0 since Sep 2016
Monthly snapshots
2 since 2016
Barry-warsaw's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store