Indian Computer Emergency Response Team (CERT-In)
First CVE: Feb 9, 2022Active for: 4 years
141
CVEs Published
More CVEs Published than 74% of tracked CNAs
28.2
Avg CVEs / Year
More Avg CVEs / Year than 76% of tracked CNAs
7.1
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Indian Computer Emergency Response Team (CERT-In) over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 9, 2022
4 years ago
Most Recent CVE
Jun 8, 2026
46 days ago
Top CVEs
All CVEs published by Indian Computer Emergency Response Team (CERT-In) as a CNA, regardless of affected vendor or product.
141 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-37569HIGH This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping component. A remote authenticated attacker could exploit this by | Aug 8, 2023 | 8.8 | 48 | NO | YES |
CVE-2026-9506HIGH This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remote attacker could exploit this | Jun 8, 2026 | 8.7 | 35 | NO | NO |
CVE-2026-45433HIGH This vulnerability exists in GX Earth 2022 ONT models due to the presence of hardcoded RSA private key within the device firmware. A remote attacker could exploit this vulnerabilit | Jun 4, 2026 | 8.7 | 34 | NO | NO |
CVE-2026-42518HIGH This vulnerability exists in e-Sushrut due to disclosure of sensitive information and hardcoded AES encryption keys in client-side JavaScript. An unauthenticated remote attacker co | Apr 29, 2026 | 8.7 | 32 | NO | NO |
CVE-2026-42514HIGH This vulnerability exists in e-Sushrut due to exposure of OTPs in plaintext within API responses. A remote attacker could exploit this vulnerability by intercepting API responses c | Apr 29, 2026 | 8.8 | 32 | NO | NO |
CVE-2026-42513HIGH This vulnerability exists in e-Sushrut due to improper authentication logic that relies on client-side response parameters to determine authentication status. A remote attacker cou | Apr 29, 2026 | 8.8 | 32 | NO | NO |
CVE-2026-45432HIGH This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in its web management interface. A remote attacker could exploit | Jun 4, 2026 | 8.7 | 31 | NO | NO |
CVE-2026-45431HIGH This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic functions in its web management interface. An authenticated | Jun 4, 2026 | 8.7 | 31 | NO | NO |
CVE-2023-30467CRITICAL This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to improper authorization at the Mi | Apr 28, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-40628CRITICAL This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper control of cod | Sep 23, 2022 | 9.8 | 31 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA141 CVEs
44%
45%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (2.8%)
Network107 (75.9%)
Unknown0 (0.0%)
Physical22 (15.6%)
Adjacent Network4 (2.8%)
Attack Complexity
Low129 (91.5%)
High12 (8.5%)
Unknown0 (0.0%)
User Interaction
None117 (83.0%)
Unknown0 (0.0%)
Required21 (14.9%)
Privileges Required
Low52 (36.9%)
High5 (3.5%)
None84 (59.6%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (141 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.7% of CVEs· 79th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Indian Computer Emergency Response Team (CERT-In) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Indian Computer Emergency Response Team (CERT-In) as a CNA — matched by CVE ID, not by organization name.