CERT/CC
First CVE: Mar 16, 2005Active for: 21 years
3,081
CVEs Published
More CVEs Published than 95% of tracked CNAs
140.0
Avg CVEs / Year
More Avg CVEs / Year than 92% of tracked CNAs
6.4
Avg CVSS Score
Higher Avg CVSS Score than 22% of tracked CNAs
0.2%
In CISA KEV
Higher KEV Rate than 81% of tracked CNAs
Trends Over Time
The number and severity of CVEs published by CERT/CC over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 16, 2005
21 years ago
Most Recent CVE
Jul 23, 2026
1 day ago
Top CVEs
All CVEs published by CERT/CC as a CNA, regardless of affected vendor or product.
3,081 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-1555CRITICAL (1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP3 | Apr 21, 2017 | 9.8 | 99 | YES | YES |
CVE-2012-1823CRITICAL sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) | May 11, 2012 | 9.8 | 99 | YES | YES |
CVE-2020-9054CRITICAL Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthen | Mar 4, 2020 | 9.8 | 98 | YES | YES |
CVE-2020-10148CRITICAL The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to b | Dec 29, 2020 | 9.8 | 97 | YES | YES |
CVE-2016-5674CRITICAL __debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attacke | Aug 31, 2016 | 9.8 | 93 | NO | YES |
CVE-2010-0219HIGH Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, whi | Oct 18, 2010 | 10.0 | 92 | NO | YES |
CVE-2016-1524CRITICAL Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary Java code by using (1) fileUp | Feb 13, 2016 | 9.6 | 90 | NO | YES |
CVE-2013-6955HIGH webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 allows remote attackers to append data to | Jan 9, 2014 | 10.0 | 89 | NO | YES |
CVE-2012-5958HIGH Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK f | Jan 31, 2013 | 10.0 | 88 | NO | YES |
CVE-2016-6563CRITICAL Processing malformed SOAP messages when performing the HNAP Login action causes a buffer overflow in the stack in some D-Link DIR routers. The vulnerable XML fields within the SOAP | Jul 13, 2018 | 9.8 | 87 | NO | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA3,081 CVEs
66%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCriticalUnknown
Attack Vector
Local136 (4.4%)
Network634 (20.6%)
Unknown2,235 (72.5%)
Physical18 (0.6%)
Adjacent Network58 (1.9%)
Attack Complexity
Low737 (23.9%)
High109 (3.5%)
Unknown2,235 (72.5%)
User Interaction
None692 (22.5%)
Unknown2,235 (72.5%)
Required154 (5.0%)
Privileges Required
Low158 (5.1%)
High22 (0.7%)
None666 (21.6%)
Unknown2,235 (72.5%)
Exploit Exposure
Signals from CVEs in this cna scope (3081 CVEs).
CISA KEV
7 CVEs
0.2% of CVEs· 81st percentile
Metasploit
91 CVEs
3.0% of CVEs· 94th percentile
Nuclei
14 CVEs
0.5% of CVEs· 75th percentile
ExploitDB
290 CVEs
9.4% of CVEs· 98th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by CERT/CC as a CNA.
Media Mentions
Media articles that mention a CVE ID published by CERT/CC as a CNA — matched by CVE ID, not by organization name.