Vulnerability Monitor

The vendors, products, and vulnerabilities you care about
foreman Vendor: theforeman

About This Product

foreman is a software product offered by theforeman. This product is widely deployed in production environments, making vulnerability monitoring essential for organizations relying on it. Security vulnerabilities in products of this category can affect system availability, data confidentiality, and integrity across entire networks. The significant number of reported vulnerabilities indicates this product has received substantial security scrutiny and community focus over time. Regular assessment of known vulnerabilities and timely patching are fundamental components of responsible system administration for any deployment of this software.

Vulnerability Landscape Summary

SecUtils has identified 70 known vulnerabilities affecting theforeman foreman. This includes 2 critical-severity issues and 20 high-severity issues that warrant immediate attention. Vulnerabilities in this product have been disclosed spanning from 2013 to 2026, indicating a sustained research interest and ongoing security attention. 47 medium-severity issues and 1 low-severity issue complete the vulnerability landscape. Organizations should prioritize patching based on deployment context, asset criticality, and exploitation likelihood rather than severity alone.

Known Vulnerabilities
ID Date Published Last Modified Severity (CVSSv3) Severity (CVSSv2) Exploit Available
CVE-2013-2113 2013-07-31 2025-04-11 - 6.0 Unknown
CVE-2013-2121 2013-07-31 2025-04-11 - 6.0 Unknown
CVE-2013-4180 2013-09-16 2025-04-11 - 5.0 Likely
CVE-2013-4182 2013-09-16 2025-04-11 - 7.5 Likely
CVE-2013-4386 2013-11-20 2025-04-11 - 7.5 Likely
CVE-2014-0089 2014-03-27 2025-04-12 - 4.3 Likely
CVE-2012-5648 2014-04-04 2025-04-12 - 7.5 Likely
CVE-2012-5477 2014-05-08 2025-04-12 - 3.6 Unknown
CVE-2013-0171 2014-05-08 2025-04-12 - 7.5 Likely
CVE-2013-0173 2014-05-08 2025-04-12 - 5.0 Likely
CVE-2013-0174 2014-05-08 2025-04-12 - 5.0 Likely
CVE-2013-0187 2014-05-08 2025-04-12 - 6.5 Likely
CVE-2013-0210 2014-05-08 2025-04-12 - 7.5 Likely
CVE-2014-0090 2014-05-08 2025-04-12 - 6.8 Likely
CVE-2014-0192 2014-05-08 2025-04-12 - 5.0 Likely
CVE-2014-0007 2014-06-20 2025-04-12 - 7.5 Likely
CVE-2014-4507 2014-06-20 2025-04-12 - 6.4 Likely
CVE-2014-3491 2014-07-01 2025-04-12 - 4.3 Likely
CVE-2014-3492 2014-07-01 2025-04-12 - 4.3 Likely
CVE-2014-3691 2015-03-09 2025-04-12 - 7.5 Likely
CVE-2014-3653 2015-07-06 2025-04-12 - 4.3 Likely
CVE-2015-1816 2015-08-14 2025-04-12 - 5.0 Likely
CVE-2015-1844 2015-08-14 2025-04-12 - 4.0 Likely
CVE-2015-3155 2015-08-14 2025-04-12 - 5.0 Likely
CVE-2015-3235 2015-08-14 2025-04-12 - 6.0 Unknown
CVE-2015-7518 2015-12-17 2025-04-12 - 4.3 Likely
CVE-2015-5233 2016-04-11 2025-04-12 4.2 6.0 Unknown
CVE-2016-2100 2016-05-20 2025-04-12 5.4 6.5 Likely
CVE-2016-3728 2016-05-20 2025-04-12 8.8 6.8 Likely
CVE-2016-4451 2016-08-19 2025-04-12 5.0 6.0 Unknown
CVE-2016-4475 2016-08-19 2025-04-12 8.8 6.5 Likely
CVE-2016-4995 2016-08-19 2025-04-12 5.3 3.5 Unknown
CVE-2016-5390 2016-08-19 2025-04-12 5.3 3.5 Unknown
CVE-2016-6319 2016-08-19 2025-04-12 6.1 4.3 Likely
CVE-2016-6320 2016-08-19 2025-04-12 5.4 3.5 Unknown
CVE-2017-7505 2017-05-26 2025-04-20 8.8 6.5 Likely
CVE-2015-5152 2017-07-17 2025-04-20 8.1 4.3 Likely
CVE-2015-5282 2017-09-25 2025-04-20 6.1 4.3 Likely
CVE-2015-5246 2017-10-06 2025-04-20 8.1 6.8 Likely
CVE-2014-0208 2017-10-16 2025-04-20 5.4 3.5 Unknown
CVE-2014-3531 2017-10-18 2025-04-20 5.4 3.5 Unknown
CVE-2017-15100 2017-11-27 2025-04-20 6.1 4.3 Likely
CVE-2018-1097 2018-04-04 2024-11-21 8.8 4.0 Likely
CVE-2018-1096 2018-04-05 2024-11-21 6.5 4.0 Likely
CVE-2016-9593 2018-04-16 2024-11-21 4.7 4.0 Likely
CVE-2017-2672 2018-06-21 2024-11-21 6.5 4.0 Likely
CVE-2017-7535 2018-07-26 2024-11-21 6.1 4.3 Likely
CVE-2016-8613 2018-07-31 2024-11-21 6.4 4.3 Likely
CVE-2016-8634 2018-08-01 2024-11-21 6.1 3.5 Unknown
CVE-2016-8639 2018-08-01 2024-11-21 6.1 3.5 Unknown
CVE-2016-7077 2018-09-10 2024-11-21 4.3 4.0 Likely
CVE-2016-7078 2018-09-10 2024-11-21 4.3 4.0 Likely
CVE-2018-14643 2018-09-21 2024-11-21 9.8 10.0 Likely
CVE-2018-14664 2018-10-12 2024-11-21 5.4 3.5 Unknown
CVE-2018-16861 2018-12-07 2024-11-21 7.6 3.5 Unknown
CVE-2019-3893 2019-04-09 2024-11-21 4.9 4.0 Likely
CVE-2014-8183 2019-08-01 2024-11-21 7.4 6.5 Likely
CVE-2014-0091 2019-12-11 2024-11-21 5.3 5.0 Likely
CVE-2021-3494 2021-04-26 2024-11-21 5.9 4.3 Likely
CVE-2021-3469 2021-06-03 2024-11-21 5.4 3.5 Unknown
CVE-2021-3584 2021-12-23 2024-11-21 7.2 9.0 Likely
CVE-2020-10710 2022-08-16 2024-11-21 4.4 - -
CVE-2021-3590 2022-08-22 2024-11-21 8.8 - -
CVE-2021-20260 2022-08-26 2024-11-21 7.8 - -
CVE-2023-0118 2023-09-20 2024-11-21 9.1 - -
CVE-2023-0462 2023-09-20 2024-11-21 8.0 - -
CVE-2022-3874 2023-09-22 2024-11-21 8.0 - -
CVE-2023-4886 2023-10-03 2024-11-21 6.7 - -
CVE-2024-7700 2024-08-12 2024-09-16 6.5 - -
CVE-2025-9572 2026-02-27 2026-03-24 5.0 - -

How SecUtils Interprets Product Data

SecUtils normalizes and enriches National Vulnerability Database (NVD) records for theforeman foreman by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and structuring the data for rapid analysis and asset correlation. For every vulnerability listed, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference information to enable organizations to prioritize patching and risk assessment efficiently. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for vulnerability management and security operations.