Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Perimeter/
  3. Perimeter VRM

Perimeter VRM

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 17 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

End-to-end vendor risk management platform with AI-powered doc analysis.

by Perimeter · perimeter.net · source ↗

Known CVEs (17)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-23609 ↗MEDIUM 5.42026

    GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Perimeter SMTP Servers configuration page. An authenticated user can supply HTML/JavaScript in t…

  • CVE-2025-10544 ↗2025

    Unrestricted file upload vulnerability in DocAve 6.13.2, Perimeter 1.12.3, Compliance Guardian 4.7.1, and earlier versions, allowing administrator users to upload files without proper validation. An a…

  • CVE-2024-12236 ↗MEDIUM 5.52024

    A security issue exists in Vertex Gemini API for customers using VPC-SC. By utilizing a custom crafted file URI for image input, data exfiltration is possible due to requests being routed outside the …

  • CVE-2022-34321 ↗HIGH 8.22024

    Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication. The vulnerable endpoint exposes detailed statistics abou…

  • CVE-2023-50129 ↗MEDIUM 6.52024

    Missing encryption in the NFC tags of the Flient Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original tags, which results in an attacker gaining ac…

  • CVE-2023-26059 ↗MEDIUM 6.82023

    An issue was discovered in Nokia NetAct before 22 SP1037. On the Site Configuration Tool tab, attackers can upload a ZIP file which, when processed, exploits Stored XSS. The upload option of the Site …

  • CVE-2022-38212 ↗HIGH 7.52022

    Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8.1 and below were not fully honored and may allow a remote, unauthenticated atta…

  • CVE-2022-38211 ↗HIGH 7.52022

    Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.9.1 and below were not fully honored and may allow a remote, unauthenticated atta…

  • CVE-2022-38203 ↗HIGH 7.52022

    Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8.1 and below were not fully honored and may allow a remote, unauthenticated atta…

  • CVE-2021-22815 ↗MEDIUM 5.32022

    A CWE-200: Information Exposure vulnerability exists which could cause the troubleshooting archive to be accessed. Affected Products: 1-Phase Uninterruptible Power Supply (UPS) using NMC2 including Sm…

  • CVE-2021-22814 ↗MEDIUM 6.12022

    A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists which could cause arbritrary script execution when a malicious file is read and disp…

  • CVE-2021-22813 ↗MEDIUM 6.12022

    A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause arbritrary script execution when a privileged account clicks on a m…

  • CVE-2021-22812 ↗MEDIUM 6.12022

    A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause arbritrary script execution when a privileged account clicks on a m…

  • CVE-2021-22811 ↗MEDIUM 6.12022

    A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause script execution when the request of a privileged account accessing…

  • CVE-2021-22810 ↗MEDIUM 6.12022

    A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause arbritrary script execution when a privileged account clicks on a m…

  • CVE-2021-28674 ↗MEDIUM 5.42021

    The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node (outside of the attacker's perimeter) via an account with write permissions. Thi…

  • CVE-2008-1182 ↗MEDIUM 4.32008

    Cross-site scripting (XSS) vulnerability in BSD Perimeter pfSense before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other GRC & Compliance Automation products

see all →
  • 3rdRisk Platform · 3rdRisk Solutions B.V.
  • 3rdcomply · 3rdcomply
  • 6clicks GRC · 6clicks
  • A-LIGN A-SCEND · A-LIGN
  • ANOZR WAY AY PeopleSight · ANOZR WAY
  • ARCON Security Compliance Management · ARCON
  • ASPIA Audit Management · ASPIA Infotech Pvt. Ltd.
  • ASPIA KRI Module · ASPIA Infotech Pvt. Ltd.