EU Agency for Cybersecurity (ENISA)
First CVE: May 27, 2024Active for: 2 years
56
CVEs Published
More CVEs Published than 60% of tracked CNAs
18.7
Avg CVEs / Year
More Avg CVEs / Year than 66% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by EU Agency for Cybersecurity (ENISA) over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 27, 2024
2 years ago
Most Recent CVE
Jul 2, 2026
21 days ago
Top CVEs
All CVEs published by EU Agency for Cybersecurity (ENISA) as a CNA, regardless of affected vendor or product.
56 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33587CRITICAL Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Te | May 7, 2026 | 10.0 | 37 | NO | NO |
CVE-2024-26291HIGH An Unauthenticated Arbitrary File Read vulnerability affects the
Agent when installed on a system. The parameter filename does not validate the
path thus allowing users to read arb | Jul 14, 2025 | 8.7 | 35 | NO | YES |
CVE-2026-33592HIGH An unauthenticated remote attacker can exhaust
server memory via the FindServers Discovery Service in open62541. The
serverUris field of FindServersRequest is not validated for len | Jul 2, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-22313CRITICAL The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attack | Jun 16, 2026 | 9.1 | 34 | NO | NO |
CVE-2026-33590HIGH Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administr | May 28, 2026 | 8.5 | 34 | NO | NO |
CVE-2026-22314CRITICAL Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other u | May 20, 2026 | 9.0 | 33 | NO | NO |
CVE-2026-33583HIGH Exposure of the QKEY (used as
input into the ‘OTA-Quantum’ device registration process) and internal
system keys via an unauthenticated and unencrypted HTTP GET method in the Arq | May 13, 2026 | 8.7 | 33 | NO | NO |
CVE-2026-22312HIGH The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get access to system settings, modify | Jun 16, 2026 | 8.6 | 32 | NO | NO |
CVE-2026-27849CRITICAL Due to missing neutralization of special elements, OS commands can be injected via the update functionality of a TLS-SRP connection, which is normally used for configuring devices | Feb 25, 2026 | 9.8 | 32 | NO | NO |
CVE-2025-27020CRITICAL Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file system
.
This issue affects | Dec 8, 2025 | 9.8 | 32 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA56 CVEs
34%
43%
21%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local9 (16.1%)
Network45 (80.4%)
Unknown0 (0.0%)
Physical2 (3.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low53 (94.6%)
High3 (5.4%)
Unknown0 (0.0%)
User Interaction
None46 (82.1%)
Unknown0 (0.0%)
Required6 (10.7%)
Privileges Required
Low15 (26.8%)
High13 (23.2%)
None28 (50.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (56 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.8% of CVEs· 85th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by EU Agency for Cybersecurity (ENISA) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by EU Agency for Cybersecurity (ENISA) as a CNA — matched by CVE ID, not by organization name.