Dutch Institute for Vulnerability Disclosure (DIVD)
First CVE: Feb 21, 2022Active for: 4 years
107
CVEs Published
More CVEs Published than 71% of tracked CNAs
21.4
Avg CVEs / Year
More Avg CVEs / Year than 69% of tracked CNAs
7.9
Avg CVSS Score
Higher Avg CVSS Score than 85% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Dutch Institute for Vulnerability Disclosure (DIVD) over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 21, 2022
4 years ago
Most Recent CVE
Jul 17, 2026
7 days ago
Top CVEs
All CVEs published by Dutch Institute for Vulnerability Disclosure (DIVD) as a CNA, regardless of affected vendor or product.
107 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22103CRITICAL The NPC start endpoint on the web server at port 8090 is vulnerable to command injection. | Jul 13, 2026 | 9.3 | 40 | NO | NO |
CVE-2026-22102CRITICAL A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint accepts the filename parameter in the Content-Disposition header | Jul 13, 2026 | 9.3 | 40 | NO | NO |
CVE-2026-22096CRITICAL The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such as configured passwords, or uploading files through different | Jul 13, 2026 | 9.3 | 40 | NO | NO |
CVE-2024-27115CRITICAL A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files that | Sep 11, 2024 | 9.8 | 40 | NO | YES |
CVE-2026-22098CRITICAL Various sensitive information such as passwords and charging card UIDs are written to log files. | Jul 13, 2026 | 9.2 | 39 | NO | NO |
CVE-2026-22097CRITICAL The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the firmware update capability to upload arbitrary files which | Jul 13, 2026 | 9.3 | 39 | NO | NO |
CVE-2026-22095CRITICAL The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection. | Jul 13, 2026 | 9.3 | 39 | NO | NO |
CVE-2026-22093CRITICAL The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided by the server. This allows an attacker on the network path be | Jul 13, 2026 | 9.5 | 39 | NO | NO |
CVE-2026-22100HIGH The OCPP DataTransfer message `ReserveLogin` is vulnerable to command injection. By manipulating the data value, arbitrary OS commands can be executed as root. | Jul 13, 2026 | 8.6 | 37 | NO | NO |
CVE-2026-22099HIGH The charging station does not require authentication for Bluetooth commands to perform actions. The functionality exposed includes sensitive information leakage, triggering reboots | Jul 13, 2026 | 8.7 | 37 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA107 CVEs
25%
40%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (3.7%)
Network97 (90.7%)
Unknown0 (0.0%)
Physical3 (2.8%)
Adjacent Network1 (0.9%)
Attack Complexity
Low107 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None93 (86.9%)
Unknown0 (0.0%)
Required13 (12.1%)
Privileges Required
Low40 (37.4%)
High8 (7.5%)
None59 (55.1%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (107 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
1.9% of CVEs· 85th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Dutch Institute for Vulnerability Disclosure (DIVD) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Dutch Institute for Vulnerability Disclosure (DIVD) as a CNA — matched by CVE ID, not by organization name.