CERT/CC

First CVE: Mar 16, 2005Active for: 21 years
3,081
CVEs Published
More CVEs Published than 95% of tracked CNAs
140.0
Avg CVEs / Year
More Avg CVEs / Year than 92% of tracked CNAs
6.4
Avg CVSS Score
Higher Avg CVSS Score than 22% of tracked CNAs
0.2%
In CISA KEV
Higher KEV Rate than 81% of tracked CNAs

Trends Over Time

The number and severity of CVEs published by CERT/CC over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 16, 2005
21 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs

All CVEs published by CERT/CC as a CNA, regardless of affected vendor or product.

3,081 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP3
Apr 21, 20179.899YESYES
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign)
May 11, 20129.899YESYES
Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthen
Mar 4, 20209.898YESYES
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to b
Dec 29, 20209.897YESYES
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attacke
Aug 31, 20169.893NOYES
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, whi
Oct 18, 201010.092NOYES
Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary Java code by using (1) fileUp
Feb 13, 20169.690NOYES
webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 allows remote attackers to append data to
Jan 9, 201410.089NOYES
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK f
Jan 31, 201310.088NOYES
Processing malformed SOAP messages when performing the HNAP Login action causes a buffer overflow in the stack in some D-Link DIR routers. The vulnerable XML fields within the SOAP
Jul 13, 20189.887NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA3,081 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCriticalUnknown
Attack Vector
Local136 (4.4%)
Network634 (20.6%)
Unknown2,235 (72.5%)
Physical18 (0.6%)
Adjacent Network58 (1.9%)
Attack Complexity
Low737 (23.9%)
High109 (3.5%)
Unknown2,235 (72.5%)
User Interaction
None692 (22.5%)
Unknown2,235 (72.5%)
Required154 (5.0%)
Privileges Required
Low158 (5.1%)
High22 (0.7%)
None666 (21.6%)
Unknown2,235 (72.5%)

Exploit Exposure

Signals from CVEs in this cna scope (3081 CVEs).

CISA KEV
7 CVEs
0.2% of CVEs· 81st percentile
Metasploit
91 CVEs
3.0% of CVEs· 94th percentile
Nuclei
14 CVEs
0.5% of CVEs· 75th percentile
ExploitDB
290 CVEs
9.4% of CVEs· 98th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by CERT/CC as a CNA.

Media Mentions

Media articles that mention a CVE ID published by CERT/CC as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs