Israel National Cyber Directorate (INCD)
First CVE: Sep 1, 2021Active for: 5 years
259
CVEs Published
More CVEs Published than 82% of tracked CNAs
43.2
Avg CVEs / Year
More Avg CVEs / Year than 82% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Israel National Cyber Directorate (INCD) over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 1, 2021
4 years ago
Most Recent CVE
May 14, 2026
71 days ago
Top CVEs
All CVEs published by Israel National Cyber Directorate (INCD) as a CNA, regardless of affected vendor or product.
259 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-55049CRITICAL Use of Default Cryptographic Key (CWE-1394) | Sep 9, 2025 | 9.1 | 32 | NO | NO |
CVE-2022-36779CRITICAL PROSCEND - PROSCEND / ADVICE .Ltd - G/5G Industrial Cellular Router (with GPS)4 Unauthenticated OS Command Injection Proscend M330-w / M33-W5 / M350-5G / M350-W5G / M350-6 / M350-W | Sep 13, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-36784CRITICAL
Elsight – Elsight Halo Remote Code Execution (RCE)
Elsight Halo web panel allows us to perform connection validation.
through the POST request :
/api/v1/nics/wifi/wlan0/ping
we c | Nov 17, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-23168CRITICAL The attacker could get access to the database. The SQL injection is in the username parameter at the login panel: username: admin'-- | Jun 13, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-22794CRITICAL Cybonet - PineApp Mail Relay Unauthenticated Sql Injection. Attacker can send a request to: /manage/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /admin/emailrichment/userlist.php | Feb 24, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-36722CRITICAL Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dumping the whole database to full RCE on the affected endpoint | Dec 29, 2021 | 9.8 | 31 | NO | NO |
CVE-2025-55058CRITICAL CWE-20 Improper Input Validation | Nov 17, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-55055CRITICAL CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | Nov 17, 2025 | 9.8 | 30 | NO | NO |
CVE-2024-45252CRITICAL Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | Oct 6, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-45249CRITICAL Cavok – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Oct 6, 2024 | 9.8 | 30 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA259 CVEs
36%
39%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local16 (6.2%)
Network232 (89.6%)
Unknown0 (0.0%)
Physical3 (1.2%)
Adjacent Network8 (3.1%)
Attack Complexity
Low257 (99.2%)
High2 (0.8%)
Unknown0 (0.0%)
User Interaction
None206 (79.5%)
Unknown0 (0.0%)
Required53 (20.5%)
Privileges Required
Low67 (25.9%)
High12 (4.6%)
None180 (69.5%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (259 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Israel National Cyber Directorate (INCD) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Israel National Cyber Directorate (INCD) as a CNA — matched by CVE ID, not by organization name.