Boa
cpe:2.3:*:boa
- Published vulnerabilities
- 10
- Products with a CVE
- 2
- In CISA KEV
- None
- Scope
- All products in namespace
Discontinued embedded web server still shipping in current devices.
Vulnerabilities by year of publication
| Year | Published CVEs |
|---|---|
| 2022 | 2 |
| 2021 | 1 |
| 2019 | 2 |
| 2017 | 1 |
| 2016 | 1 |
| 2010 | 1 |
| 2007 | 1 |
| 2000 | 1 |
Year of CVE publication, not of discovery or of the affected product's release. A spike usually reflects a single researcher's disclosure batch rather than a change in product quality.
Products
Most recent CVEs
| CVE | Published | CVSS | Severity | EPSS | Flags |
|---|---|---|---|---|---|
| CVE-2022-45956 | 2022-12-12 | 5.3 | medium | 0.8% | Exploit ref |
| CVE-2022-44117 | 2022-11-23 | 9.8 | critical | 0.7% | |
| CVE-2021-33558 | 2021-05-27 | 7.5 | high | 12.3% | Exploit ref |
| CVE-2018-21028 | 2019-10-11 | 7.5 | high | 2.1% | Vendor advisory |
| CVE-2018-21027 | 2019-10-11 | 9.8 | critical | 2.4% | Vendor advisory |
| CVE-2017-9833 | 2017-06-24 | 7.5 | high | 68.5% | Exploit ref |
| CVE-2016-9564 | 2016-11-30 | 7.5 | high | 1.4% | Exploit ref |
| CVE-2009-4496 | 2010-01-13 | 5.0 | medium | 12.1% | Exploit ref |
| CVE-2007-4915 | 2007-09-17 | 10.0 | high | 68.2% | |
| CVE-2000-0920 | 2000-12-19 | 5.0 | medium | 8.4% | Vendor advisory |
Counts cover CVEs whose NVD CPE configuration names a product in the boa namespace. A vendor with few CVEs is not necessarily a vendor with few vulnerabilities — see coverage and gaps.