Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Manifest

Manifest

enriched
AI / LLM SecurityApplication Security (ASPM)Software Supply Chain SecurityVulnerability Management

manifestcyber.com ↗ · required email domain for this vendor's users

Do you work at Manifest?

This profile was built from public sources and hasn't been claimed yet. Claiming it lets you correct what's wrong and add details only you can confirm — and marks that information as vendor-verified for buyers.

Free, and it does not affect ranking, placement, or comparison results. The first person verified on Manifest's email domain becomes the profile admin.

Claim this profileAlready have an account?

Trust profileHow to read thisFive separate questions a buyer actually asks, each answered with its own evidence and a link to the source. There is deliberately no overall score: a single number invites comparison it cannot support, and would mostly reflect how much of Manifest we have managed to scan rather than anything about the vendor.

Not checked means we have not looked yet, and is never counted against a vendor. Limited means we did look, but found only one line of evidence — enough to report, not enough to corroborate.

checked 6 of 16 signals
  • Limited

    Independently verified

    Has anyone other than the vendor confirmed this?

    checked 3 of 4

    Nothing here has been confirmed by an independent third party yet.

    • No third-party certifications found
    • Profile not claimed by the vendor
  • Limited

    Operating durability

    Is this a real, durable business?

    checked 2 of 4

    How long this vendor has been operating, and who stands behind them.

    • Headquarters location not disclosed on their site
  • Mixed

    Behaviour under stress

    What do they do when something goes wrong?

    checked 1 of 3

    What their public record shows about handling vulnerabilities and outages.

    • 71 published CVE(s) — a public disclosure record exists
    • 7 rated critical
  • Not checked

    Disclosure posture

    Do they tell you the awkward things unprompted?

    checked 0 of 3

    We have not checked what this vendor discloses publicly yet.

    Nothing checked here yet — this is not a mark against Manifest.

  • Not checked

    Momentum

    Are they still shipping, or coasting?

    checked 0 of 2

    We have not tracked this vendor's release activity yet.

    Nothing checked here yet — this is not a mark against Manifest.

Data coverage: 10/100What this measures (and doesn't)

Not a quality rating or endorsement — a measure of how much verified, disclosed data we actually have about this vendor. A low score usually means "we don't have much verified information yet," not "this is a bad vendor." Never used to sort or rank vendor lists.

Verification depth0/100
Security signal0/100
Buyer feedbackno data yet (0 reviews so far)
Profile completeness0/100
claim · HQ · materials · screenshots · integrations · certifications · security check

The platform admin controls the formula's weights.

Data coverage profileHow to read thisThe same four components behind the data coverage score above, shaped instead of listed — a vendor strong on verification but thin on buyer feedback looks visibly different from one that's the other way around. Security and feedback plot at the neutral midpoint (50) when there's no data yet (no products tracked, no reviews), matching how the actual score itself treats missing data — not a guess either way.

VerificationSecurityFeedbackCompletenessThis vendor — Verification: 0This vendor — Security: 0This vendor — Feedback: no data yetThis vendor — Completeness: 0

Buyer reviewsUI-14 — verified-buyer reviewsWritten only by domain-verified buyers at other companies, attributed to their company domain (never their identity), and moderated. Buyer-sourced opinion, clearly separate from the neutral catalog facts above — and never an input to search or comparison ordering.

verified buyers only

No buyer reviews yet.

Reputation ratingUI-20 — anonymous ratingA single anonymous 5-star signal from buyers, resellers, and analysts who've engaged with this vendor — separate from the domain-attributed reviews above. No rater identity is ever shown, not even at company level.

anonymous

No ratings in this window yet.

Creates structured inventories of AI system components for transparency & risk mgmt AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →

CVE severity over timeUI-24 — CVE severity timelineEvery known CVE with a disclosure date and severity, plotted by when it was published — lets you see whether disclosures are trending toward more or less severe, not just a raw count. Same NVD-sourced, name-matched data as the list below.

LOWMEDIUMHIGHCRITICAL20052006200720082009201020112012201320142015201620172018201920202021202220232024CVE-2023-50726 · MEDIUM 6.4 · 2024-03-13CVE-2023-46918 · MEDIUM 4.6 · 2023-12-27CVE-2023-6862 · HIGH 8.8 · 2023-12-19CVE-2023-36620 · MEDIUM 4.6 · 2023-11-03CVE-2023-38552 · HIGH 7.5 · 2023-10-18CVE-2023-42471 · CRITICAL 9.8 · 2023-09-11CVE-2023-40040 · MEDIUM 5.3 · 2023-09-11CVE-2023-40584 · MEDIUM 6.5 · 2023-09-07CVE-2023-39532 · CRITICAL 9.8 · 2023-08-08CVE-2023-35934 · MEDIUM 6.1 · 2023-07-06CVE-2023-3027 · HIGH 7.8 · 2023-06-05CVE-2023-33293 · MEDIUM 5.3 · 2023-05-22CVE-2022-4457 · MEDIUM 5.5 · 2023-01-11CVE-2022-34471 · MEDIUM 6.5 · 2022-12-22CVE-2022-31691 · CRITICAL 9.8 · 2022-11-04CVE-2022-31036 · MEDIUM 4.3 · 2022-06-27CVE-2022-24904 · MEDIUM 4.3 · 2022-05-20CVE-2022-0675 · MEDIUM 5.6 · 2022-03-02CVE-2022-21682 · HIGH 7.7 · 2022-01-13CVE-2021-43388 · HIGH 7.5 · 2021-12-14CVE-2021-42306 · HIGH 8.1 · 2021-11-24CVE-2021-41190 · LOW 3.0 · 2021-11-17CVE-2021-29486 · HIGH 7.5 · 2021-04-30CVE-2021-21386 · CRITICAL 9.3 · 2021-03-24CVE-2021-21285 · MEDIUM 6.5 · 2021-02-02CVE-2020-26278 · MEDIUM 5.8 · 2021-01-20CVE-2020-26271 · MEDIUM 4.4 · 2020-12-10CVE-2020-15157 · MEDIUM 6.1 · 2020-10-16CVE-2020-0387 · HIGH 7.8 · 2020-09-17CVE-2020-5417 · HIGH 8.8 · 2020-08-21CVE-2020-12415 · MEDIUM 6.5 · 2020-07-09CVE-2020-11614 · HIGH 8.1 · 2020-06-11CVE-2020-11075 · HIGH 7.7 · 2020-05-28CVE-2019-11994 · CRITICAL 9.8 · 2020-01-03CVE-2014-8179 · HIGH 7.5 · 2019-12-17CVE-2019-11271 · HIGH 7.8 · 2019-06-19CVE-2018-13901 · MEDIUM 5.5 · 2019-06-14CVE-2018-13895 · HIGH 7.8 · 2019-05-24CVE-2018-17983 · CRITICAL 9.1 · 2018-10-04CVE-2016-8651 · LOW 3.1 · 2018-08-01CVE-2018-5112 · HIGH 7.5 · 2018-06-11CVE-2017-7807 · HIGH 8.1 · 2018-06-11CVE-2016-10632 · HIGH 8.1 · 2018-06-01CVE-2016-10574 · HIGH 8.1 · 2018-06-01CVE-2016-10564 · HIGH 8.1 · 2018-05-31CVE-2017-17833 · CRITICAL 9.8 · 2018-04-23CVE-2015-4082 · MEDIUM 6.5 · 2017-08-18CVE-2017-11468 · HIGH 7.5 · 2017-07-20CVE-2017-9443 · HIGH 8.8 · 2017-06-05CVE-2017-9441 · LOW 2.7 · 2017-06-05CVE-2016-7055 · MEDIUM 5.9 · 2017-05-04CVE-2016-10159 · HIGH 7.5 · 2017-01-24CVE-2016-10100 · MEDIUM 5.3 · 2017-01-03CVE-2016-10099 · MEDIUM 5.3 · 2017-01-03CVE-2016-5162 · MEDIUM 6.5 · 2016-09-11CVE-2016-5160 · MEDIUM 6.5 · 2016-09-11CVE-2015-5223 · MEDIUM 5.0 · 2015-10-26CVE-2015-3408 · HIGH 10.0 · 2015-05-19CVE-2014-3543 · MEDIUM 4.3 · 2014-07-29CVE-2014-3496 · HIGH 10.0 · 2014-06-20CVE-2013-6470 · MEDIUM 5.0 · 2014-06-02CVE-2012-6119 · LOW 2.1 · 2013-04-03CVE-2012-2665 · HIGH 7.5 · 2012-08-06CVE-2011-4596 · MEDIUM 6.0 · 2011-12-24CVE-2011-3828 · HIGH 9.3 · 2011-11-26CVE-2009-2348 · MEDIUM 6.9 · 2009-07-17CVE-2008-5354 · HIGH 9.3 · 2008-12-05CVE-2007-0412 · MEDIUM 5.0 · 2007-01-23CVE-2006-5585 · HIGH 7.2 · 2006-12-13CVE-2005-0820 · MEDIUM 5.0 · 2005-05-02CVE-2004-1958 · MEDIUM 5.0 · 2004-12-31

Known CVEs (71)About this listSourced from the public NVD database, matched by vendor name. This is a name-based match, not exact version tracking — always check the linked NVD record for affected versions before drawing conclusions. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2023-50726 ↗MEDIUM 6.42024

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows developers to temporarily override an Application's manifests with locally-defi…

  • CVE-2023-46918 ↗MEDIUM 4.62023

    Phlox com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus has an Android manifest file that contains an entry with the android:allowBackup attribute set to true. This could be leverag…

  • CVE-2023-6862 ↗HIGH 8.82023

    A use-after-free was identified in the `nsDNSService::Init`. This issue appears to manifest rarely during start-up. This vulnerability affects Firefox ESR < 115.6 and Thunderbird < 115.6.

  • CVE-2023-36620 ↗MEDIUM 4.62023

    An issue was discovered in the Boomerang Parental Control application before 13.83 for Android. The app is missing the android:allowBackup="false" attribute in the manifest. This allows the user to ba…

  • CVE-2023-38552 ↗HIGH 7.52023

    When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementat…

  • CVE-2023-42471 ↗CRITICAL 9.82023

    The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It contains a manifest entry that exports the wave.ai.bro…

  • CVE-2023-40040 ↗MEDIUM 5.32023

    An issue was discovered in the MyCrops HiGrade "THC Testing & Cannabi" application 1.0.337 for Android. A remote attacker can start the camera feed via the com.cordovaplugincamerapreview.CameraActivit…

  • CVE-2023-40584 ↗MEDIUM 6.52023

    Argo CD is a declarative continuous deployment for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug where the ArgoCD repo-server component is vulnerable to a Denial-of-Service attack v…

  • CVE-2023-39532 ↗CRITICAL 9.82023

    SES is a JavaScript environment that allows safe execution of arbitrary programs in Compartments. In version 0.18.0 prior to 0.18.7, 0.17.0 prior to 0.17.1, 0.16.0 prior to 0.16.1, 0.15.0 prior to 0.1…

  • CVE-2023-35934 ↗MEDIUM 6.12023

    yt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp or the external downloaders that yt-dlp employs may leak cookies on HTTP redirects to a different ho…

  • CVE-2023-3027 ↗HIGH 7.82023

    The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained values (instead of the policy apply a static manifest on…

  • CVE-2023-33293 ↗MEDIUM 5.32023

    An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on *.localhost with subdomains for each installed applications, e.g., myapp.localhost. An a…

  • CVE-2022-4457 ↗MEDIUM 5.52023

    Due to a misconfiguration in the manifest file of the WARP client for Android, it was possible to a perform a task hijacking attack. An attacker could create a malicious mobile application which could…

  • CVE-2022-34471 ↗MEDIUM 6.52022

    When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, a…

  • CVE-2022-31691 ↗CRITICAL 9.82022

    Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39…

  • CVE-2022-31036 ↗MEDIUM 4.32022

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.3.0 are vulnerable to a symlink following bug allowing a malicious user with reposito…

  • CVE-2022-24904 ↗MEDIUM 4.32022

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.7.0 and prior to versions 2.1.15m 2.2.9, and 2.3.4 is vulnerable to a symlink following bug al…

  • CVE-2022-0675 ↗MEDIUM 5.62022

    In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unmanaged rules to exist …

  • CVE-2022-21682 ↗HIGH 7.72022

    Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and 1.10.6. flatpak-builder applies `finish-args` last …

  • CVE-2021-43388 ↗HIGH 7.52021

    Unisys Cargo Mobile Application before 1.2.29 uses cleartext to store sensitive information, which might be revealed in a backup. The issue is addressed by ensuring that the allowBackup flag (in the m…

  • …and 51 more

Competitors (12)

full alternatives comparison →
aDolus TechnologyAI EdgeLabsApiiroAppCheckAqua SecurityArnicaBlack DuckBoostSecurityCloudMatosCodenotaryLabrador LabsWiz

Products (5)

Vulnerability Management

1
  • Manifest Vulnerability ManagementAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Automated vulnerability mgmt platform with risk-based prioritization & SBOM

Application Security (ASPM)

1
  • Manifest PlatformAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    SBOM management platform for software supply chain compliance and governance

AI / LLM Security

1
  • Manifest AI Bill of Materials (AIBOM)AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Creates structured inventories of AI system components for transparency & risk mgmt

Software Supply Chain Security

2
  • Manifest Cyber Manifest PlatformAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Platform for securing software supply chain, AI models, and vendor software
  • Manifest SBOMsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Automated SBOM generation and management platform for software supply chain