Cyber Security Agency of Singapore
First CVE: Jun 24, 2025Active for: 1 year
21
CVEs Published
More CVEs Published than 41% of tracked CNAs
10.5
Avg CVEs / Year
More Avg CVEs / Year than 55% of tracked CNAs
6.9
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked CNAs
4.8%
In CISA KEV
Higher KEV Rate than 96% of tracked CNAs
Trends Over Time
The number and severity of CVEs published by Cyber Security Agency of Singapore over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 24, 2025
12 months ago
Most Recent CVE
Jul 13, 2026
11 days ago
Top CVEs
All CVEs published by Cyber Security Agency of Singapore as a CNA, regardless of affected vendor or product.
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-52691CRITICAL Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code | Dec 29, 2025 | 10.0 | 98 | YES | YES |
CVE-2025-52694CRITICAL Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exp | Jan 12, 2026 | 9.8 | 67 | NO | YES |
CVE-2025-52688CRITICAL Successful exploitation of the vulnerability could allow an attacker to inject commands with root privileges on the access point, potentially leading to the loss of confidentiality | Jul 16, 2025 | 9.8 | 42 | NO | NO |
CVE-2026-7162HIGH Successful
exploitation of the integer overflow vulnerability could allow an attacker to
achieve system-level access to the affected software. | Jul 13, 2026 | 7.8 | 37 | NO | NO |
CVE-2025-52689CRITICAL Successful exploitation of the vulnerability could allow an unauthenticated attacker to obtain a valid session ID with administrator privileges by spoofing the login request, poten | Jul 16, 2025 | 9.8 | 36 | NO | NO |
CVE-2026-3006HIGH Successful exploitation of the race condition vulnerability could allow
an attacker to trigger a kernel heap overflow, potentially leading to local privilege
escalation and grantin | Apr 27, 2026 | 7.0 | 34 | NO | NO |
CVE-2026-3008MEDIUM Successful exploitation of the
string injection vulnerability could allow an attacker to obtain memory address
information or crash the application. | Apr 27, 2026 | 6.6 | 32 | NO | NO |
CVE-2025-52692HIGH Successful exploitation of the vulnerability could allow an attacker with local network access to send a specially crafted URL to access certain administration functions without lo | Dec 19, 2025 | 8.8 | 32 | NO | NO |
CVE-2026-6888HIGH Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to
execute arbitrary commands via a specific interface,
potentially enabling | May 13, 2026 | 7.2 | 29 | NO | NO |
CVE-2025-48469CRITICAL Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public update page, potentially leading to backdoor installation o | Jun 24, 2025 | 9.6 | 29 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA21 CVEs
10%
38%
29%
24%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (19.0%)
Network8 (38.1%)
Unknown0 (0.0%)
Physical1 (4.8%)
Adjacent Network8 (38.1%)
Attack Complexity
Low13 (61.9%)
High8 (38.1%)
Unknown0 (0.0%)
User Interaction
None16 (76.2%)
Unknown0 (0.0%)
Required5 (23.8%)
Privileges Required
Low3 (14.3%)
High4 (19.0%)
None14 (66.7%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (21 CVEs).
CISA KEV
1 CVE
4.8% of CVEs· 96th percentile
Metasploit
1 CVE
4.8% of CVEs· 96th percentile
Nuclei
2 CVEs
9.5% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Cyber Security Agency of Singapore as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Cyber Security Agency of Singapore as a CNA — matched by CVE ID, not by organization name.