Dutch Institute for Vulnerability Disclosure (DIVD)

First CVE: Feb 21, 2022Active for: 4 years
107
CVEs Published
More CVEs Published than 71% of tracked CNAs
21.4
Avg CVEs / Year
More Avg CVEs / Year than 69% of tracked CNAs
7.9
Avg CVSS Score
Higher Avg CVSS Score than 85% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by Dutch Institute for Vulnerability Disclosure (DIVD) over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 21, 2022
4 years ago
Most Recent CVE
Jul 17, 2026
7 days ago

Top CVEs

All CVEs published by Dutch Institute for Vulnerability Disclosure (DIVD) as a CNA, regardless of affected vendor or product.

107 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The NPC start endpoint on the web server at port 8090 is vulnerable to command injection.
Jul 13, 20269.340NONO
A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint accepts the filename parameter in the Content-Disposition header
Jul 13, 20269.340NONO
The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such as configured passwords, or uploading files through different
Jul 13, 20269.340NONO
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files that
Sep 11, 20249.840NOYES
Various sensitive information such as passwords and charging card UIDs are written to log files.
Jul 13, 20269.239NONO
The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the firmware update capability to upload arbitrary files which
Jul 13, 20269.339NONO
The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection.
Jul 13, 20269.339NONO
The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided by the server. This allows an attacker on the network path be
Jul 13, 20269.539NONO
The OCPP DataTransfer message `ReserveLogin` is vulnerable to command injection. By manipulating the data value, arbitrary OS commands can be executed as root.
Jul 13, 20268.637NONO
The charging station does not require authentication for Bluetooth commands to perform actions. The functionality exposed includes sensitive information leakage, triggering reboots
Jul 13, 20268.737NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA107 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local4 (3.7%)
Network97 (90.7%)
Unknown0 (0.0%)
Physical3 (2.8%)
Adjacent Network1 (0.9%)
Attack Complexity
Low107 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None93 (86.9%)
Unknown0 (0.0%)
Required13 (12.1%)
Privileges Required
Low40 (37.4%)
High8 (7.5%)
None59 (55.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (107 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
1.9% of CVEs· 85th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Dutch Institute for Vulnerability Disclosure (DIVD) as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Dutch Institute for Vulnerability Disclosure (DIVD) as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs