National Cyber Security Centre Finland (NCSC-FI)
First CVE: Dec 20, 2024Active for: 2 years
24
CVEs Published
More CVEs Published than 45% of tracked CNAs
8.0
Avg CVEs / Year
More Avg CVEs / Year than 47% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by National Cyber Security Centre Finland (NCSC-FI) over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 20, 2024
19 months ago
Most Recent CVE
Apr 27, 2026
88 days ago
Top CVEs
All CVEs published by National Cyber Security Centre Finland (NCSC-FI) as a CNA, regardless of affected vendor or product.
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-6265HIGH Insecure preserved inherited permissions vulnerability in Cerberus FTP Server on Windows allows Privilege Escalation.This issue has been resolved in Cerberus FTP Server: 2026.1 | Apr 27, 2026 | 8.8 | 32 | NO | NO |
CVE-2026-2731CRITICAL Path traversal and content injection in JobRunnerBackground.aspx in DynamicWeb 8 (all) and 9 (<9.19.7 and <9.20.3) allows unauthenticated attackers to execute code via simple web r | Feb 19, 2026 | 10.0 | 32 | NO | NO |
CVE-2025-15625CRITICAL Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases. | Apr 17, 2026 | 9.8 | 31 | NO | NO |
CVE-2025-9427HIGH Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Lemonsoft WordPress add on allows Cross-Site Scripting (XSS).This issue | Jan 13, 2026 | 8.4 | 27 | NO | NO |
CVE-2025-10009HIGH Incorrect handling of uploaded files in the admin "Restore" function in Invoice Ninja <= 5.11.72 allows attackers with admin credentials to execute arbitrary code on the server via | Sep 22, 2025 | 8.6 | 27 | NO | NO |
CVE-2025-15624HIGH Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.
In a setup where OpenID is used as the primary method of authentication to authenti | Apr 17, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-15623HIGH Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty L | Apr 17, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-3315HIGH Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical Resource vulnerability in ASSA ABLOY Visionline on Windows al | Mar 10, 2026 | 7.8 | 25 | NO | NO |
CVE-2025-15595HIGH Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions. | Mar 3, 2026 | 7.8 | 25 | NO | NO |
CVE-2025-15554HIGH Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local adm | Mar 16, 2026 | 7.8 | 24 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA24 CVEs
25%
67%
8%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local9 (37.5%)
Network13 (54.2%)
Unknown0 (0.0%)
Physical1 (4.2%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (95.8%)
High1 (4.2%)
Unknown0 (0.0%)
User Interaction
None19 (79.2%)
Unknown0 (0.0%)
Required1 (4.2%)
Privileges Required
Low9 (37.5%)
High4 (16.7%)
None11 (45.8%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (24 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by National Cyber Security Centre Finland (NCSC-FI) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by National Cyber Security Centre Finland (NCSC-FI) as a CNA — matched by CVE ID, not by organization name.