Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

zitadel

About This Vendor

zitadel is a technology vendor producing software and infrastructure products. As a software provider, zitadel's broad product portfolio across multiple domains—including operating systems, cloud infrastructure, enterprise applications, databases, networking, and security tools—creates a large attack surface. Additionally, long support cycles, widespread deployment, and continuous feature development contribute to the accumulation of discovered vulnerabilities over time. Major vendors typically report higher CVE counts not necessarily due to inferior security, but because of greater exposure to security research, responsible disclosure practices, and the sheer complexity of maintaining multiple product lines and legacy systems. Regular security assessments and patching of zitadel's products are critical for organizations running their software in production environments.

Vulnerability Trends for This Vendor

SecUtils has indexed 47 known vulnerabilities from zitadel. This includes 6 critical-severity issues and 23 high-severity issues that represent significant risk. These vulnerabilities affect 1 distinct product across zitadel's portfolio, demonstrating the breadth of the vendor's product ecosystem and the importance of comprehensive patch management strategies. Disclosure dates span from 2022 through 2026, with recent active disclosure activity. Organizations deploying zitadel products should maintain active vulnerability monitoring, prioritize critical patches, and implement compensating controls where patches cannot be applied immediately.

ID Date Published Last Modified Severity (CVSSv3) Severity (CVSSv2) Exploit Available
CVE-2022-36051 2022-08-31 2024-11-21 8.7 - -
CVE-2023-22492 2023-01-11 2024-11-21 5.9 - -
CVE-2023-44399 2023-10-10 2024-11-21 5.3 - -
CVE-2023-46238 2023-10-26 2024-11-21 8.7 - -
CVE-2023-47111 2023-11-08 2024-11-21 7.3 - -
CVE-2023-49097 2023-11-30 2024-11-21 8.1 - -
CVE-2024-28197 2024-03-11 2025-01-07 7.5 - -
CVE-2024-28855 2024-03-18 2025-01-08 8.1 - -
CVE-2024-29891 2024-03-27 2025-01-08 8.7 - -
CVE-2024-29892 2024-03-27 2025-01-08 6.1 - -
CVE-2024-32868 2024-04-26 2025-01-08 6.5 - -
CVE-2024-32967 2024-05-01 2025-01-08 5.3 - -
CVE-2024-39683 2024-07-03 2025-01-08 5.7 - -
CVE-2024-41952 2024-07-31 2025-01-08 5.3 - -
CVE-2024-41953 2024-07-31 2025-01-08 4.3 - -
CVE-2024-46999 2024-09-20 2024-09-24 7.3 - -
CVE-2024-47000 2024-09-20 2024-09-24 8.1 - -
CVE-2024-47060 2024-09-20 2024-09-25 4.3 - -
CVE-2024-49753 2024-10-25 2025-08-26 5.9 - -
CVE-2024-49757 2024-10-25 2025-08-26 7.5 - -
CVE-2025-27507 2025-03-04 2025-08-26 9.0 - -
CVE-2025-31123 2025-03-31 2025-08-26 8.7 - -
CVE-2025-31124 2025-03-31 2025-08-26 5.3 - -
CVE-2025-46815 2025-05-06 2025-08-26 8.0 - -
CVE-2025-48936 2025-05-30 2025-06-04 8.1 - -
CVE-2025-53895 2025-07-15 2025-08-26 8.8 - -
CVE-2025-57770 2025-08-22 2025-08-27 5.3 - -
CVE-2025-64101 2025-10-29 2025-11-04 8.1 - -
CVE-2025-64102 2025-10-29 2025-11-04 9.8 - -
CVE-2025-64103 2025-10-29 2025-11-04 9.8 - -
CVE-2025-64717 2025-11-13 2025-12-04 9.8 - -
CVE-2025-67494 2025-12-09 2025-12-19 9.3 - -
CVE-2025-67495 2025-12-09 2025-12-19 8.0 - -
CVE-2025-67717 2025-12-11 2026-02-02 4.3 - -
CVE-2026-23511 2026-01-15 2026-01-20 5.3 - -
CVE-2026-27840 2026-02-26 2026-03-05 4.3 - -
CVE-2026-27945 2026-02-26 2026-03-05 6.5 - -
CVE-2026-27946 2026-02-26 2026-03-05 6.5 - -
CVE-2026-29067 2026-03-07 2026-03-10 8.1 - -
CVE-2026-29191 2026-03-07 2026-03-10 9.3 - -
CVE-2026-29192 2026-03-07 2026-03-10 7.7 - -
CVE-2026-29193 2026-03-07 2026-03-10 8.2 - -
CVE-2026-32130 2026-03-11 2026-03-16 7.5 - -
CVE-2026-32131 2026-03-11 2026-03-16 7.7 - -
CVE-2026-32132 2026-03-11 2026-03-16 7.4 - -
CVE-2026-33132 2026-03-20 2026-03-23 5.3 - -
CVE-2026-44671 2026-05-14 2026-05-15 7.5 - -

How SecUtils Normalizes Vendor Data

SecUtils aggregates National Vulnerability Database (NVD) and MITRE records for zitadel by normalizing vendor identifiers across diverse data sources, mapping vendor names to their associated product lines, and collecting all known vulnerabilities under a unified vendor context. For every CVE associated with zitadel's products, we extract and structure Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) categories, CVSS severity metrics, and reference links to enable rapid vulnerability identification and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and vendor vulnerability tracking.