JPCERT/CC

First CVE: Jun 25, 2010Active for: 16 years
3,121
CVEs Published
More CVEs Published than 95% of tracked CNAs
183.6
Avg CVEs / Year
More Avg CVEs / Year than 93% of tracked CNAs
6.7
Avg CVSS Score
Higher Avg CVSS Score than 31% of tracked CNAs
0.2%
In CISA KEV
Higher KEV Rate than 80% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by JPCERT/CC as a CNA, 0.3% affect products that JPCERT/CC develops as a vendor.

99.7%
Self-reported: 9Third-party: 3,112

Of all the CVEs published that affect products developed by JPCERT/CC, 100.0% are self-published by JPCERT/CC as a CNA.

100.0%
Self-published: 9Published by other CNAs: 0

Trends Over Time

The number and severity of CVEs published by JPCERT/CC over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 25, 2010
16 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs

All CVEs published by JPCERT/CC as a CNA, regardless of affected vendor or product.

3,121 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and earlier (Movable Type Advanced
Oct 26, 20219.889NOYES
An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an ar
Dec 6, 20238.887YESNO
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
Jan 9, 20199.885NOYES
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.
May 14, 20169.880NOYES
SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.
Jun 9, 20179.878YESNO
Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrar
Oct 20, 20259.876YESNO
Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000
Jul 10, 20148.375NOYES
FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arb
Feb 13, 20268.874YESNO
Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthe
Apr 18, 20259.870YESNO
CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a
Dec 19, 20229.869NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA3,121 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local455 (14.6%)
Network1,853 (59.4%)
Unknown580 (18.6%)
Physical26 (0.8%)
Adjacent Network207 (6.6%)
Attack Complexity
Low2,402 (77.0%)
High139 (4.5%)
Unknown580 (18.6%)
User Interaction
None1,379 (44.2%)
Unknown580 (18.6%)
Required1,162 (37.2%)
Privileges Required
Low581 (18.6%)
High234 (7.5%)
None1,726 (55.3%)
Unknown580 (18.6%)

Exploit Exposure

Signals from CVEs in this cna scope (3121 CVEs).

CISA KEV
6 CVEs
0.2% of CVEs· 80th percentile
Metasploit
3 CVEs
0.1% of CVEs· 78th percentile
Nuclei
14 CVEs
0.4% of CVEs· 74th percentile
ExploitDB
9 CVEs
0.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by JPCERT/CC as a CNA.

Media Mentions

Media articles that mention a CVE ID published by JPCERT/CC as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs