CVE Tools

Enterprise Security Manager

21 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Enterprise Security Manager, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.

Enterprise Security Manager CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Enterprise Security Manager CVEs per month
MonthCVEs
2024-100
2024-112
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 21 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical210%
  • High1152%
  • Medium838%

Latest CVEs

The 15 most recently published vulnerabilities affecting Enterprise Security Manager.

  1. CVE-2024-11482A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.9.8
  2. CVE-2024-11481A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, insecure forwarding to an AJP backend without adequa...8.2
  3. CVE-2023-6071 An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administrator to execute arbitrary code as root on the ESM. This is po...8.4
  4. CVE-2023-6070 A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possi...4.3
  5. CVE-2023-3314 A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands used to control the process execution of the .zi...8.1
  6. CVE-2023-3313 An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed an unauthorized user to execute system command injection f...7.8
  7. CVE-2019-3644MWG scanners updated to address CVE-2019-95177.5
  8. CVE-2019-3643MWG scanners updated to address CVE-2019-95115.3
  9. CVE-2019-3632Directory Traversal vulnerability could lead to elevated privileges8.8
  10. CVE-2019-3631Command Injection could allow authenticated users to execute arbitrary code7.2
  11. CVE-2019-3630Command Injection could allow authenticated users to execute arbitrary code7.2
  12. CVE-2019-3629Application protections bypass vulnerability could allow unauthenticated user to impersonate system users6.5
  13. CVE-2019-3628Privilege escalation could allow authenticated user to gain access to a core system8.8
  14. CVE-2018-11784When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '...4.3
  15. CVE-2015-7704The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store