Spanish National Cybersecurity Institute, S.A. (INCIBE)
First CVE: Apr 1, 2020Active for: 6 years
1,096
CVEs Published
More CVEs Published than 91% of tracked CNAs
156.6
Avg CVEs / Year
More Avg CVEs / Year than 92% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Spanish National Cybersecurity Institute, S.A. (INCIBE) over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 1, 2020
6 years ago
Most Recent CVE
Jul 14, 2026
10 days ago
Top CVEs
All CVEs published by Spanish National Cybersecurity Institute, S.A. (INCIBE) as a CNA, regardless of affected vendor or product.
1,096 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-4045CRITICAL TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. | Mar 10, 2022 | 9.8 | 77 | NO | YES |
CVE-2024-5315CRITICAL Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query t | May 24, 2024 | 9.1 | 56 | NO | YES |
CVE-2025-10353CRITICAL File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a maliciou | Oct 8, 2025 | 9.3 | 47 | NO | YES |
CVE-2022-2025CRITICAL an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy ins | Sep 23, 2022 | 9.8 | 46 | NO | YES |
CVE-2022-2070CRITICAL In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf instruction. Because of that, a | Sep 23, 2022 | 9.8 | 44 | NO | YES |
CVE-2026-12257CRITICAL Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. The flaw is located in the endpoint “/index.cfm/_api/json/v1/default”, where th | Jul 13, 2026 | 9.3 | 41 | NO | NO |
CVE-2026-12686CRITICAL An authenticated user could manipulate a company ID parameter in a POST request to the backend to gain unauthorised access to other companies hosted within the same subdomain envir | Jul 6, 2026 | 9.3 | 40 | NO | NO |
CVE-2026-9508CRITICAL Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly exposed when the administrator conf | May 29, 2026 | 10.0 | 39 | NO | NO |
CVE-2025-41373HIGH A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, | Aug 1, 2025 | 8.8 | 38 | NO | YES |
CVE-2026-15389HIGH A vulnerability relating to insufficient access control has been identified in the session management of the Sesame Time web application and its REST v3 API. The flaw lies in the f | Jul 14, 2026 | 8.7 | 36 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA1,096 CVEs
53%
29%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local66 (6.0%)
Network1,013 (92.4%)
Unknown0 (0.0%)
Physical2 (0.2%)
Adjacent Network12 (1.1%)
Attack Complexity
Low1,074 (98.0%)
High22 (2.0%)
Unknown0 (0.0%)
User Interaction
None601 (54.8%)
Unknown0 (0.0%)
Required418 (38.1%)
Privileges Required
Low324 (29.6%)
High37 (3.4%)
None735 (67.1%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (1096 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
5 CVEs
0.5% of CVEs· 75th percentile
ExploitDB
5 CVEs
0.5% of CVEs· 77th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Spanish National Cybersecurity Institute, S.A. (INCIBE) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Spanish National Cybersecurity Institute, S.A. (INCIBE) as a CNA — matched by CVE ID, not by organization name.