Black Lantern Security

First CVE: Jul 14, 2023Active for: 3 years
19
CVEs Published
More CVEs Published than 38% of tracked CNAs
6.3
Avg CVEs / Year
More Avg CVEs / Year than 39% of tracked CNAs
6.3
Avg CVSS Score
Higher Avg CVSS Score than 17% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by Black Lantern Security over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 14, 2023
3 years ago
Most Recent CVE
Jul 8, 2026
16 days ago

Top CVEs

All CVEs published by Black Lantern Security as a CNA, regardless of affected vendor or product.

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly sanitized before being incorporated into a SQL query, allowi
Jun 4, 20269.839NONO
An unauthenticated SQL Injection was discovered within the Geutebruck G-Cam E-Series Cameras through the `Group` parameter in the `/uapi-cgi/viewer/Param.cgi` script. This has been
Nov 3, 20259.834NONO
BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting in remote code execution.
Oct 9, 20259.634NONO
A blind XML External Entity (XXE) injection in the OpenMessaging webservice in TecCom TecConnect 4.1 allows an unauthenticated attacker to exfiltrate arbitrary files to an attacker
Sep 9, 20259.132NONO
BBOT's gitdumper module could be abused to execute commands through a malicious git repository.
Oct 9, 20259.631NONO
Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, database connection strings, and API keys. The encryption keys
Feb 6, 20267.827NONO
The postman_download module uses the workspace name field from the Postman API to construct the local directory path without sanitization. If a malicious workspace has a name conta
Jun 17, 20266.525NONO
A Cross-Site Request Forgery (CSRF) vulnerability exists in the product image upload function of VirtueMart that bypasses the CSRF protection token. An attacker is able to craft a
Jun 11, 20258.323NONO
The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, relying entirely on the behavior of external tools (e.g. GNU t
Jun 17, 20265.321NONO
An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated attackers can upload files with arbitrary extensions, includi
Jun 11, 20257.221NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA19 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local3 (15.8%)
Network16 (84.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (73.7%)
High5 (26.3%)
Unknown0 (0.0%)
User Interaction
None6 (31.6%)
Unknown0 (0.0%)
Required13 (68.4%)
Privileges Required
Low4 (21.1%)
High1 (5.3%)
None14 (73.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Black Lantern Security as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Black Lantern Security as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs