Israel National Cyber Directorate (INCD)

First CVE: Sep 1, 2021Active for: 5 years
259
CVEs Published
More CVEs Published than 82% of tracked CNAs
43.2
Avg CVEs / Year
More Avg CVEs / Year than 82% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by Israel National Cyber Directorate (INCD) over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 1, 2021
4 years ago
Most Recent CVE
May 14, 2026
71 days ago

Top CVEs

All CVEs published by Israel National Cyber Directorate (INCD) as a CNA, regardless of affected vendor or product.

259 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Use of Default Cryptographic Key (CWE-1394)
Sep 9, 20259.132NONO
PROSCEND - PROSCEND / ADVICE .Ltd - G/5G Industrial Cellular Router (with GPS)4 Unauthenticated OS Command Injection Proscend M330-w / M33-W5 / M350-5G / M350-W5G / M350-6 / M350-W
Sep 13, 20229.832NONO
Elsight – Elsight Halo  Remote Code Execution (RCE) Elsight Halo web panel allows us to perform connection validation. through the POST request : /api/v1/nics/wifi/wlan0/ping we c
Nov 17, 20229.831NONO
The attacker could get access to the database. The SQL injection is in the username parameter at the login panel: username: admin'--
Jun 13, 20229.831NONO
Cybonet - PineApp Mail Relay Unauthenticated Sql Injection. Attacker can send a request to: /manage/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /admin/emailrichment/userlist.php
Feb 24, 20229.831NONO
Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dumping the whole database to full RCE on the affected endpoint
Dec 29, 20219.831NONO
CWE-20 Improper Input Validation
Nov 17, 20259.830NONO
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Nov 17, 20259.830NONO
Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Oct 6, 20249.830NONO
Cavok – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Oct 6, 20249.830NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA259 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local16 (6.2%)
Network232 (89.6%)
Unknown0 (0.0%)
Physical3 (1.2%)
Adjacent Network8 (3.1%)
Attack Complexity
Low257 (99.2%)
High2 (0.8%)
Unknown0 (0.0%)
User Interaction
None206 (79.5%)
Unknown0 (0.0%)
Required53 (20.5%)
Privileges Required
Low67 (25.9%)
High12 (4.6%)
None180 (69.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (259 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Israel National Cyber Directorate (INCD) as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Israel National Cyber Directorate (INCD) as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs