Keyfactor records
11 published records for vendor keyfactor.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-284 Improper Access Control3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-287 Improper Authentication1
- CWE-642 External Control of Critical State Data1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-33872No exploit | Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code execution and escalation of CWE-89 | Critical9.8 | — | 0.5% | Aug 20, 2024 |
32Monitor | CVE-2023-34196No exploit | In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an akeyfactor · ejbca · CWE-287 | High8.2 | — | 0.4% | Aug 2, 2023 |
30Monitor | CVE-2024-42006No exploit | Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure.keyfactor · aws orchestrator · CWE-200 | High7.5 | — | 0.4% | Aug 20, 2024 |
30Monitor | CVE-2024-34458No exploit | Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in information disclosure.keyfactor · command · CWE-89 | High7.5 | — | 0.4% | Aug 20, 2024 |
26Monitor | CVE-2025-47222No exploit | A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2.keyfactor · signserver · CWE-284 | Medium6.5 | — | 0.3% | Nov 13, 2025 |
21Monitor | CVE-2022-39834No exploit | A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2.keyfactor · primekey ejbca · CWE-79 | Medium5.4 | — | 0.4% | Nov 17, 2022 |
21Monitor | CVE-2022-42954No exploit | Keyfactor EJBCA before 7.10.0 allows XSS.keyfactor · kefactor ejbca · CWE-79 | Medium5.4 | — | 0.4% | Nov 17, 2022 |
21Monitor | CVE-2025-47220No exploit | A local file enumeration was found in Keyfactor SignServer versions prior to 7.3.2 .The property VISIBLE_SIGNATURE_CUSTOM_IMAGE_PATH, which keyfactor · signserver · CWE-284 | Medium5.3 | — | 0.3% | Nov 13, 2025 |
21Monitor | CVE-2025-47221No exploit | An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2.keyfactor · signserver · CWE-284 | Medium5.3 | — | 0.2% | Nov 13, 2025 |
18Monitor | CVE-2025-26787No exploit | An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2.keyfactor · signserver · CWE-642 | Medium4.7 | — | 0.1% | Dec 22, 2025 |
12Monitor | CVE-2024-36066No exploit | The CMP CLI client in KeyFactor EJBCA before 8.3.1 has only 6 octets of salt, and is thus not compliant with the security requirements of RFkeyfactor · ejbca | Low3.1 | — | 0.2% | Sep 12, 2024 |
- CVE-2024-3387239Monitor
Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code execution and escalation of
CriticalCVSS 9.8No exploitEPSS 0%Aug 20, 2024
- CVE-2023-3419632Monitor
In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an a
HighCVSS 8.2No exploitEPSS 0%keyfactor · ejbcaAug 2, 2023
- CVE-2024-4200630Monitor
Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure.
HighCVSS 7.5No exploitEPSS 0%keyfactor · aws orchestratorAug 20, 2024
- CVE-2024-3445830Monitor
Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in information disclosure.
HighCVSS 7.5No exploitEPSS 0%keyfactor · commandAug 20, 2024
- CVE-2025-4722226Monitor
A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2.
MediumCVSS 6.5No exploitEPSS 0%keyfactor · signserverNov 13, 2025
- CVE-2022-3983421Monitor
A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2.
MediumCVSS 5.4No exploitEPSS 0%keyfactor · primekey ejbcaNov 17, 2022
- CVE-2022-4295421Monitor
Keyfactor EJBCA before 7.10.0 allows XSS.
MediumCVSS 5.4No exploitEPSS 0%keyfactor · kefactor ejbcaNov 17, 2022
- CVE-2025-4722021Monitor
A local file enumeration was found in Keyfactor SignServer versions prior to 7.3.2 .The property VISIBLE_SIGNATURE_CUSTOM_IMAGE_PATH, which
MediumCVSS 5.3No exploitEPSS 0%keyfactor · signserverNov 13, 2025
- CVE-2025-4722121Monitor
An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2.
MediumCVSS 5.3No exploitEPSS 0%keyfactor · signserverNov 13, 2025
- CVE-2025-2678718Monitor
An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2.
MediumCVSS 4.7No exploitEPSS 0%keyfactor · signserverDec 22, 2025
- CVE-2024-3606612Monitor
The CMP CLI client in KeyFactor EJBCA before 8.3.1 has only 6 octets of salt, and is thus not compliant with the security requirements of RF
LowCVSS 3.1No exploitEPSS 0%keyfactor · ejbcaSep 12, 2024