Black Lantern Security
First CVE: Jul 14, 2023Active for: 3 years
19
CVEs Published
More CVEs Published than 38% of tracked CNAs
6.3
Avg CVEs / Year
More Avg CVEs / Year than 39% of tracked CNAs
6.3
Avg CVSS Score
Higher Avg CVSS Score than 17% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Black Lantern Security over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 14, 2023
3 years ago
Most Recent CVE
Jul 8, 2026
16 days ago
Top CVEs
All CVEs published by Black Lantern Security as a CNA, regardless of affected vendor or product.
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-10880CRITICAL OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly sanitized before being incorporated into a SQL query, allowi | Jun 4, 2026 | 9.8 | 39 | NO | NO |
CVE-2025-12463CRITICAL An unauthenticated SQL Injection was discovered within the Geutebruck G-Cam E-Series Cameras through the `Group` parameter in the `/uapi-cgi/viewer/Param.cgi` script. This has been | Nov 3, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-10284CRITICAL BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting in remote code execution. | Oct 9, 2025 | 9.6 | 34 | NO | NO |
CVE-2025-10183CRITICAL A blind XML External Entity (XXE) injection in the OpenMessaging webservice in TecCom TecConnect 4.1 allows an unauthenticated attacker to exfiltrate arbitrary files to an attacker | Sep 9, 2025 | 9.1 | 32 | NO | NO |
CVE-2025-10283CRITICAL BBOT's gitdumper module could be abused to execute commands through a malicious git repository. | Oct 9, 2025 | 9.6 | 31 | NO | NO |
CVE-2026-2103HIGH Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, database connection strings, and API keys. The encryption keys | Feb 6, 2026 | 7.8 | 27 | NO | NO |
CVE-2026-12568MEDIUM The postman_download module uses the workspace name field from the Postman API to construct the local directory path without sanitization. If a malicious workspace has a name conta | Jun 17, 2026 | 6.5 | 25 | NO | NO |
CVE-2025-6001HIGH A Cross-Site Request Forgery (CSRF) vulnerability exists in the product image upload function of VirtueMart that bypasses the CSRF protection token. An attacker is able to craft a | Jun 11, 2025 | 8.3 | 23 | NO | NO |
CVE-2026-12565MEDIUM The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, relying entirely on the behavior of external tools (e.g. GNU t | Jun 17, 2026 | 5.3 | 21 | NO | NO |
CVE-2025-6002HIGH An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated attackers can upload files with arbitrary extensions, includi | Jun 11, 2025 | 7.2 | 21 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA19 CVEs
21%
37%
16%
26%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (15.8%)
Network16 (84.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (73.7%)
High5 (26.3%)
Unknown0 (0.0%)
User Interaction
None6 (31.6%)
Unknown0 (0.0%)
Required13 (68.4%)
Privileges Required
Low4 (21.1%)
High1 (5.3%)
None14 (73.7%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Black Lantern Security as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Black Lantern Security as a CNA — matched by CVE ID, not by organization name.