Switzerland National Cyber Security Centre (NCSC)

First CVE: Nov 16, 2021Active for: 5 years
164
CVEs Published
More CVEs Published than 77% of tracked CNAs
27.3
Avg CVEs / Year
More Avg CVEs / Year than 75% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by Switzerland National Cyber Security Centre (NCSC) over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 16, 2021
4 years ago
Most Recent CVE
Jul 22, 2026
2 days ago

Top CVEs

All CVEs published by Switzerland National Cyber Security Centre (NCSC) as a CNA, regardless of affected vendor or product.

164 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal vulnerability in the identifier parameter of /api.app/attachment/preview that allows
May 8, 20268.841NONO
Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack. When Unblu Spark is deployed with com.unblu.identifier
Jul 22, 20269.340NONO
Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session IDs (aka Session Replay). This issue affects Avantra: before
May 22, 20269.639NONO
The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged
Jul 22, 20268.838NONO
Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The
May 29, 202610.038NONO
A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code execution as root on the server sid
May 8, 202610.037NONO
SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI, allowing remote attackers to obtain
May 8, 20266.936NONO
SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code execution in the new GINA UI because an endpoint passes attacker-controlled input from a pa
May 8, 20269.335NONO
SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to reset a victim account password.
Apr 2, 20269.835NONO
ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.36 in Java applications, allows an attacker to execute arbitr
Jun 24, 20267.034NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA164 CVEs
Severity distribution among all CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local17 (10.4%)
Network135 (82.3%)
Unknown0 (0.0%)
Physical4 (2.4%)
Adjacent Network2 (1.2%)
Attack Complexity
Low149 (90.9%)
High15 (9.1%)
Unknown0 (0.0%)
User Interaction
None124 (75.6%)
Unknown0 (0.0%)
Required25 (15.2%)
Privileges Required
Low41 (25.0%)
High13 (7.9%)
None110 (67.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (164 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
0.6% of CVEs· 77th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Switzerland National Cyber Security Centre (NCSC) as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Switzerland National Cyber Security Centre (NCSC) as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs