CERT.PL
First CVE: Sep 5, 2023Active for: 3 years
452
CVEs Published
More CVEs Published than 86% of tracked CNAs
113.0
Avg CVEs / Year
More Avg CVEs / Year than 90% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by CERT.PL over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 5, 2023
2 years ago
Most Recent CVE
Jul 22, 2026
2 days ago
Top CVEs
All CVEs published by CERT.PL as a CNA, regardless of affected vendor or product.
452 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-0868CRITICAL A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of JSON data using eval() an unauthorized attacker could send | Feb 20, 2025 | 9.3 | 57 | NO | YES |
CVE-2026-6847CRITICAL Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload function. The application exposes an endpoint that allows unau | Jul 13, 2026 | 9.3 | 41 | NO | NO |
CVE-2026-40469CRITICAL Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing t | Jul 13, 2026 | 9.1 | 40 | NO | NO |
CVE-2026-40468CRITICAL Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to ove | Jul 13, 2026 | 9.1 | 40 | NO | NO |
CVE-2026-41880CRITICAL R-SOFT DMS is vulnerable to OS Command Injection in the Optical Character Recognition (OCR) module. Multiple command execution functions accept user-controllable file paths without | Jul 10, 2026 | 9.0 | 40 | NO | NO |
CVE-2026-9058CRITICAL For untrusted certificates that contain the "Authority Information Access - caIssuers URI" extension, Szafir SDK will automatically download the parent CA certificate from the spec | May 25, 2026 | 9.3 | 40 | NO | NO |
CVE-2026-57309CRITICAL A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in HTTP header resulting in Blind | Jul 20, 2026 | 9.3 | 39 | NO | NO |
CVE-2026-44089CRITICAL Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. This vulnerability could be exploited to cause the program to c | Jun 23, 2026 | 9.4 | 39 | NO | NO |
CVE-2026-42249CRITICAL Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP response headers. When downloading up | Apr 29, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-42248CRITICAL Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows implementation of the update verifi | Apr 29, 2026 | 9.8 | 39 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA452 CVEs
48%
31%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local73 (16.2%)
Network315 (69.7%)
Unknown0 (0.0%)
Physical6 (1.3%)
Adjacent Network1 (0.2%)
Attack Complexity
Low436 (96.5%)
High16 (3.5%)
Unknown0 (0.0%)
User Interaction
None307 (67.9%)
Unknown0 (0.0%)
Required80 (17.7%)
Privileges Required
Low138 (30.5%)
High39 (8.6%)
None275 (60.8%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (452 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
0.4% of CVEs· 74th percentile
ExploitDB
2 CVEs
0.4% of CVEs· 76th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by CERT.PL as a CNA.
Media Mentions
Media articles that mention a CVE ID published by CERT.PL as a CNA — matched by CVE ID, not by organization name.