Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS)
First CVE: May 9, 2012Active for: 14 years
3,827
CVEs Published
More CVEs Published than 96% of tracked CNAs
255.1
Avg CVEs / Year
More Avg CVEs / Year than 95% of tracked CNAs
7.7
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked CNAs
0.4%
In CISA KEV
Higher KEV Rate than 84% of tracked CNAs
Trends Over Time
The number and severity of CVEs published by Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS) over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 9, 2012
14 years ago
Most Recent CVE
Jul 23, 2026
1 day ago
Top CVEs
All CVEs published by Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS) as a CNA, regardless of affected vendor or product.
3,827 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1709CRITICAL ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel
vulnerability, which may allow an attacker direct access to | Feb 21, 2024 | 10.0 | 99 | YES | YES |
CVE-2017-7921CRITICAL An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Bui | May 6, 2017 | 9.8 | 99 | YES | YES |
CVE-2024-1708HIGH ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker
the ability to execute remote code or directly impact confide | Feb 21, 2024 | 8.4 | 97 | YES | YES |
CVE-2014-0780CRITICAL Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequent | Apr 25, 2014 | 9.8 | 95 | YES | YES |
CVE-2021-38406HIGH Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bound | Sep 17, 2021 | 7.8 | 92 | YES | NO |
CVE-2025-1316CRITICAL Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device | Mar 5, 2025 | 9.8 | 91 | YES | NO |
CVE-2016-0854CRITICAL Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows r | Jan 15, 2016 | 9.8 | 85 | NO | YES |
CVE-2021-22681CRITICAL Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell | Mar 3, 2021 | 9.8 | 83 | YES | NO |
CVE-2018-10594CRITICAL Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, ES2, SE, SS2 and AHSIM_5x0, AHSIM_5x1) ut | Jun 26, 2018 | 9.8 | 83 | NO | YES |
CVE-2025-0994HIGH Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authen | Feb 6, 2025 | 8.8 | 82 | YES | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA3,827 CVEs
27%
47%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCriticalUnknown
Attack Vector
Local693 (18.1%)
Network2,480 (64.8%)
Unknown387 (10.1%)
Physical81 (2.1%)
Adjacent Network181 (4.7%)
Attack Complexity
Low3,244 (84.8%)
High196 (5.1%)
Unknown387 (10.1%)
User Interaction
None2,610 (68.2%)
Unknown387 (10.1%)
Required818 (21.4%)
Privileges Required
Low648 (16.9%)
High138 (3.6%)
None2,654 (69.3%)
Unknown387 (10.1%)
Exploit Exposure
Signals from CVEs in this cna scope (3827 CVEs).
CISA KEV
15 CVEs
0.4% of CVEs· 84th percentile
Metasploit
50 CVEs
1.3% of CVEs· 89th percentile
Nuclei
11 CVEs
0.3% of CVEs· 72nd percentile
ExploitDB
81 CVEs
2.1% of CVEs· 89th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS) as a CNA — matched by CVE ID, not by organization name.