Postman
Security Risk Profile
36
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 5 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from September 26, 2018 to present
5
Total CVEs
2
Critical+High
0
Exploited
2
Unpatched
Threat Assessment
Avg CVSS
7.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
36/100
low
Severity Distribution
Critical
1High
1Medium
1Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
No CWE data available
Most Affected Products
1. Postman Postman5
2. Zapier Zapier2
3. ENS Domains ENS Domains2
4. PostHog PostHog2
5. npm Node Package Manager1
Recent Vulnerabilities
See more →https://www.bleepingcomputer.com/news/security/shai-hulud-malware-infects-500-npm-packages-leaks-secrets-on-github/
unknown
Shai-Hulud malware infects 500 npm packages, leaks secrets on GitHub
11/24/2025🔧 No Patch
https://www.theregister.com/2025/11/24/shai_hulud_npm_worm/
unknown
Shai-Hulud worm returns, belches secrets to 25K GitHub repos
11/24/2025🔧 No Patch
CVE-2025-0733
CVSS 4.5medium
Postman profapi.dll untrusted search path
1/27/2025🔧 No Patch
CVE-2024-23738
CVSS 9.8EPSS 0%critical
1/28/2024🔧 No Patch
CVE-2018-17215
CVSS 8.1high
9/26/2018🔧 No Patch
Monitor Postman in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.