KrCERT/CC
First CVE: Jan 17, 2018Active for: 9 years
191
CVEs Published
More CVEs Published than 79% of tracked CNAs
21.2
Avg CVEs / Year
More Avg CVEs / Year than 69% of tracked CNAs
8.6
Avg CVSS Score
Higher Avg CVSS Score than 95% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by KrCERT/CC over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 17, 2018
8 years ago
Most Recent CVE
Feb 27, 2026
147 days ago
Top CVEs
All CVEs published by KrCERT/CC as a CNA, regardless of affected vendor or product.
191 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-5195CRITICAL Hancom NEO versions 9.6.1.5183 and earlier have a buffer Overflow vulnerability that leads remote attackers to execute arbitrary commands when performing the hyperlink Attributes i | Jan 17, 2018 | 9.8 | 32 | NO | NO |
CVE-2026-24497CRITICAL Stack-based Buffer Overflow vulnerability in SimTech Systems, Inc. ThinkWise allows Remote Code Inclusion.This issue affects ThinkWise: from 7 through 23. | Feb 27, 2026 | 9.8 | 31 | NO | NO |
CVE-2022-41158CRITICAL Remote code execution vulnerability can be achieved by using cookie values as paths to a file by this builder program. A remote attacker could exploit the vulnerability to execute | Nov 25, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-26638CRITICAL Improper Authentication vulnerability in S&D smarthome(smartcare) application can cause authentication bypass and information exposure. Remote attackers can use this vulerability t | Jun 23, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-26637CRITICAL There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the | Jun 23, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-26622CRITICAL An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute | Mar 25, 2022 | 10.0 | 31 | NO | NO |
CVE-2020-7832CRITICAL A vulnerability (improper input validation) in the DEXT5 Upload solution allows an unauthenticated attacker to download and execute an arbitrary file via AddUploadFile, SetSelectIt | Sep 7, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-26606CRITICAL A vulnerability in PKI Security Solution of Dream Security could allow arbitrary command execution. This vulnerability is due to insufficient validation of the authorization certif | Aug 6, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-26605CRITICAL An improper input validation vulnerability in the service of ezPDFReader allows attacker to execute arbitrary command. This issue occurred when the ezPDF launcher received and exec | Aug 5, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-7845CRITICAL Spamsniper 5.0 ~ 5.2.7 contain a stack-based buffer overflow vulnerability caused by improper boundary checks when parsing MAIL FROM command. It leads remote attacker to execute ar | Dec 27, 2020 | 9.8 | 31 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA191 CVEs
52%
40%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local40 (20.9%)
Network148 (77.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (1.6%)
Attack Complexity
Low187 (97.9%)
High4 (2.1%)
Unknown0 (0.0%)
User Interaction
None119 (62.3%)
Unknown0 (0.0%)
Required70 (36.6%)
Privileges Required
Low14 (7.3%)
High7 (3.7%)
None170 (89.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (191 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by KrCERT/CC as a CNA.
Media Mentions
Media articles that mention a CVE ID published by KrCERT/CC as a CNA — matched by CVE ID, not by organization name.