cirosec GmbH

First CVE: Jul 15, 2024Active for: 2 years
12
CVEs Published
More CVEs Published than 30% of tracked CNAs
6.0
Avg CVEs / Year
More Avg CVEs / Year than 37% of tracked CNAs
7.3
Avg CVSS Score
Higher Avg CVSS Score than 60% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by cirosec GmbH over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 15, 2024
2 years ago
Most Recent CVE
Jul 21, 2025
368 days ago

Top CVEs

All CVEs published by cirosec GmbH as a CNA, regardless of affected vendor or product.

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A Path traversal vulnerability in the file download functionality was identified. This vulnerability allows unauthenticated users to download arbitrary files, in the context of the
May 16, 20258.624NONO
Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5.5.6 on iOS allows local attackers to bypass b
Jul 21, 20257.823NONO
The kernel driver, accessible to low-privileged users, exposes a function that fails to properly validate the privileges of the calling process. This allows creating files at arbit
Apr 4, 20257.823NONO
Local Privilege Escalation in AVG Internet Security v24 on Windows allows a local unprivileged user to escalate privileges to SYSTEM via COM-Hijacking.
Sep 12, 20247.823NONO
Local Privilege Escalation in MSI-Installer in baramundi Management Agent v23.1.172.0 on Windows allows a local unprivileged user to escalate privileges to SYSTEM.
Jul 15, 20247.823NONO
Local privilege escalation in G DATA Security Client due to incorrect assignment of privileges to directories. This vulnerability allows a local, unprivileged attacker to escalate
Jan 25, 20257.822NONO
A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. This allows an
Sep 4, 20247.822NONO
Local privilege escalation due to incorrect assignment of privileges of temporary files in the update mechanism of G DATA Management Server. This vulnerability allows a local, unpr
Jan 25, 20257.821NONO
Cross site request forgery in Kiteworks OwnCloud allows an unauthenticated attacker to forge requests. If a request has no Authorization header, it is created with an empty string
Oct 1, 20246.820NONO
The vulnerability exists in the password storage of Mobateks MobaXterm in versions below 25.0. MobaXTerm uses an initialisation vector (IV) consisting only of zero bytes and a mast
Feb 17, 20256.519NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA12 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHigh
Attack Vector
Local9 (75.0%)
Network3 (25.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (75.0%)
High3 (25.0%)
Unknown0 (0.0%)
User Interaction
None10 (83.3%)
Unknown0 (0.0%)
Required2 (16.7%)
Privileges Required
Low8 (66.7%)
High0 (0.0%)
None4 (33.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by cirosec GmbH as a CNA.

Media Mentions

Media articles that mention a CVE ID published by cirosec GmbH as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs