Gridware Cybersecurity
First CVE: Dec 4, 2024Active for: 2 years
52
CVEs Published
More CVEs Published than 59% of tracked CNAs
17.3
Avg CVEs / Year
More Avg CVEs / Year than 64% of tracked CNAs
8.0
Avg CVSS Score
Higher Avg CVSS Score than 86% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Gridware Cybersecurity over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 4, 2024
19 months ago
Most Recent CVE
Mar 5, 2026
141 days ago
Top CVEs
All CVEs published by Gridware Cybersecurity as a CNA, regardless of affected vendor or product.
52 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1023CRITICAL A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability in the Ed | Feb 18, 2025 | 9.8 | 39 | NO | YES |
CVE-2026-28775CRITICAL An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver. The d | Mar 4, 2026 | 9.8 | 33 | NO | NO |
CVE-2025-66261CRITICAL Unauthenticated OS Command Injection (restore_settings.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, | Nov 26, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-66259CRITICAL Authenticated Root Remote Code Execution via improrer user input filtering in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 20 | Nov 26, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-66256CRITICAL Unauthenticated Arbitrary File Upload (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, | Nov 26, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-66253CRITICAL Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 60 | Nov 26, 2025 | 9.8 | 32 | NO | NO |
CVE-2026-29128CRITICAL IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) that are owned by root but world- | Mar 5, 2026 | 10.0 | 31 | NO | NO |
CVE-2025-66262CRITICAL Arbitrary File Overwrite via Tar Extraction Path Traversal in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, | Nov 26, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-66250CRITICAL Unauthenticated Arbitrary File Upload (status_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, | Nov 26, 2025 | 9.8 | 31 | NO | NO |
CVE-2026-28773HIGH The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web Management Interface version | Mar 4, 2026 | 8.8 | 30 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA52 CVEs
25%
40%
35%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local14 (26.9%)
Network38 (73.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low50 (96.2%)
High2 (3.8%)
Unknown0 (0.0%)
User Interaction
None44 (84.6%)
Unknown0 (0.0%)
Required5 (9.6%)
Privileges Required
Low25 (48.1%)
High4 (7.7%)
None23 (44.2%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (52 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.9% of CVEs· 85th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Gridware Cybersecurity as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Gridware Cybersecurity as a CNA — matched by CVE ID, not by organization name.