cirosec GmbH
First CVE: Jul 15, 2024Active for: 2 years
12
CVEs Published
More CVEs Published than 30% of tracked CNAs
6.0
Avg CVEs / Year
More Avg CVEs / Year than 37% of tracked CNAs
7.3
Avg CVSS Score
Higher Avg CVSS Score than 60% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by cirosec GmbH over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 15, 2024
2 years ago
Most Recent CVE
Jul 21, 2025
368 days ago
Top CVEs
All CVEs published by cirosec GmbH as a CNA, regardless of affected vendor or product.
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-2305HIGH A Path traversal vulnerability in the file
download functionality was identified. This vulnerability allows
unauthenticated users to download arbitrary files, in the context of the | May 16, 2025 | 8.6 | 24 | NO | NO |
CVE-2025-41459HIGH Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5.5.6 on iOS allows local attackers to bypass b | Jul 21, 2025 | 7.8 | 23 | NO | NO |
CVE-2025-1865HIGH The kernel driver, accessible to low-privileged users, exposes a function that fails to properly validate the privileges of the calling process. This allows creating files at arbit | Apr 4, 2025 | 7.8 | 23 | NO | NO |
CVE-2024-6510HIGH Local Privilege Escalation in AVG Internet Security v24 on Windows allows a local unprivileged user to escalate privileges to SYSTEM via COM-Hijacking. | Sep 12, 2024 | 7.8 | 23 | NO | NO |
CVE-2024-6689HIGH Local Privilege Escalation in MSI-Installer in baramundi Management Agent v23.1.172.0 on Windows allows a local unprivileged user to escalate privileges to SYSTEM. | Jul 15, 2024 | 7.8 | 23 | NO | NO |
CVE-2025-0543HIGH Local privilege escalation in G DATA Security Client due to incorrect assignment of privileges to directories. This vulnerability allows a local, unprivileged attacker to escalate | Jan 25, 2025 | 7.8 | 22 | NO | NO |
CVE-2024-7834HIGH A local privilege escalation is caused by Overwolf
loading and executing certain dynamic link library files from a user-writeable
folder in SYSTEM context on launch. This allows an | Sep 4, 2024 | 7.8 | 22 | NO | NO |
CVE-2025-0542HIGH Local privilege escalation due to incorrect assignment of privileges of temporary files in the update mechanism of G DATA Management Server. This vulnerability allows a local, unpr | Jan 25, 2025 | 7.8 | 21 | NO | NO |
CVE-2023-7273MEDIUM Cross site request forgery in Kiteworks OwnCloud allows an unauthenticated attacker to forge requests.
If a request has no Authorization header, it is created with an empty string | Oct 1, 2024 | 6.8 | 20 | NO | NO |
CVE-2025-0714MEDIUM The vulnerability exists in the password storage of Mobateks MobaXterm in versions below 25.0. MobaXTerm uses an initialisation vector (IV) consisting only of zero bytes and a mast | Feb 17, 2025 | 6.5 | 19 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA12 CVEs
33%
67%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local9 (75.0%)
Network3 (25.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (75.0%)
High3 (25.0%)
Unknown0 (0.0%)
User Interaction
None10 (83.3%)
Unknown0 (0.0%)
Required2 (16.7%)
Privileges Required
Low8 (66.7%)
High0 (0.0%)
None4 (33.3%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by cirosec GmbH as a CNA.
Media Mentions
Media articles that mention a CVE ID published by cirosec GmbH as a CNA — matched by CVE ID, not by organization name.