algosec CVE Vulnerabilities & Metrics

Focus on algosec vulnerabilities and metrics.

Last updated: 16 Jan 2026, 23:25 UTC

About algosec Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with algosec. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total algosec CVEs: 5
Earliest CVE date: 29 Jan 2014, 18:55 UTC
Latest CVE date: 09 Dec 2025, 16:17 UTC

Latest CVE reference: CVE-2025-12381

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 2

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): -100.0%
Year Variation (Calendar): 100.0%

Month Growth Rate (30-day Rolling): -100.0%
Year Growth Rate (365-day Rolling): 100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical algosec CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 1.61

Max CVSS: 4.3

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 5
4.0-6.9 3
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS algosec CVEs

These are the five CVEs with the highest CVSS scores for algosec, sorted by severity first and recency.

All CVEs for algosec

CVE-2025-12381 algosec vulnerability CVSS: 0 09 Dec 2025, 16:17 UTC

Improper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux, 64 bit allows Privilege Escalation, Parameter Injection. A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file.  This issue affects Firewall Analyzer: A33.0, A33.10.

CVE-2025-12382 algosec vulnerability CVSS: 0 12 Nov 2025, 10:15 UTC

Improper Limitation of a Pathname 'Path Traversal') vulnerability in Algosec Firewall Analyzer on Linux, 64 bit allows an authenticated user to upload files to a restricted directory leading to code injection. This issue affects Algosec Firewall Analyzer: A33.0 (up to build 320), A33.10 (up to build 210).

CVE-2023-46596 algosec vulnerability CVSS: 0 15 Feb 2024, 06:15 UTC

Improper input validation in Algosec FireFlow VisualFlow workflow editor via Name, Description and Configuration File field in version A32.20, A32.50, A32.60 permits an attacker to initiate an XSS attack by injecting malicious executable scripts into the application's code. Fixed in version A32.20 (b600 and above), A32.50 (b430 and above), A32.60 (b250 and above)

CVE-2023-46595 algosec vulnerability CVSS: 0 02 Nov 2023, 08:15 UTC

Net-NTLM leak via HTML injection in FireFlow VisualFlow workflow editor allows an attacker to obtain victim’s domain credentials and Net-NTLM hash which can lead to relay domain attacks. Fixed in A32.20 (b570 or above), A32.50 (b390 or above)

CVE-2022-36783 algosec vulnerability CVSS: 0 25 Oct 2022, 17:15 UTC

AlgoSec – FireFlow Reflected Cross-Site-Scripting (RXSS) A malicious user injects JavaScript code into a parameter called IntersectudRule on the search/result.html page. The malicious user changes the request from POST to GET and sends the URL to another user (victim). JavaScript code is executed on the browser of the other user.

CVE-2014-4164 algosec vulnerability CVSS: 4.3 16 Jun 2014, 18:55 UTC

Cross-site scripting (XSS) vulnerability in AlgoSec FireFlow 6.3-b230 allows remote attackers to inject arbitrary web script or HTML via a user signature to SelfService/Prefs.html.

CVE-2013-7318 algosec vulnerability CVSS: 4.3 29 Jan 2014, 18:55 UTC

Cross-site scripting (XSS) vulnerability in BusinessFlow/login in AlgoSec Firewall Analyzer 6.4 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

CVE-2013-5092 algosec vulnerability CVSS: 4.3 29 Jan 2014, 18:55 UTC

Cross-site scripting (XSS) vulnerability in afa/php/Login.php in AlgoSec Firewall Analyzer 6.1-b86 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.