National Cyber Security Centre Netherlands (NCSC-NL)
First CVE: Aug 29, 2023Active for: 3 years
39
CVEs Published
More CVEs Published than 52% of tracked CNAs
9.8
Avg CVEs / Year
More Avg CVEs / Year than 53% of tracked CNAs
8.1
Avg CVSS Score
Higher Avg CVSS Score than 89% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by National Cyber Security Centre Netherlands (NCSC-NL) over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 29, 2023
2 years ago
Most Recent CVE
Feb 20, 2026
154 days ago
Top CVEs
All CVEs published by National Cyber Security Centre Netherlands (NCSC-NL) as a CNA, regardless of affected vendor or product.
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-59818CRITICAL This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file. | Feb 4, 2026 | 9.8 | 32 | NO | NO |
CVE-2025-64093CRITICAL Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device. | Jan 9, 2026 | 9.8 | 32 | NO | NO |
CVE-2023-41918CRITICAL A vulnerability allows unauthorized access to functionality inadequately constrained by ACLs. Attackers may exploit this to unauthenticated execute commands potentially leading to | Jul 2, 2024 | 10.0 | 30 | NO | NO |
CVE-2023-43870CRITICAL When installing the Net2 software a root certificate is installed into the trusted store. A potential hacker could access the installer batch file or reverse engineer the source co | Dec 19, 2023 | 9.8 | 30 | NO | NO |
CVE-2025-64090HIGH This vulnerability allows authenticated attackers to execute commands via the hostname of the device. | Jan 9, 2026 | 8.8 | 29 | NO | NO |
CVE-2025-64091HIGH This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device. | Jan 9, 2026 | 8.8 | 28 | NO | NO |
CVE-2025-11690HIGH An Insecure Direct Object Reference (IDOR) vulnerability exists in the vehicleId parameter, allowing unauthorized access to sensitive information of other users’ vehicles. Exploiti | Nov 4, 2025 | 8.5 | 28 | NO | NO |
CVE-2025-59814HIGH This vulnerability allows malicious actors to gain unauthorized access to the Zenitel ICX500 and ICX510 Gateway Billing Admin endpoint, enabling them to read the entire contents of | Sep 25, 2025 | 8.8 | 28 | NO | NO |
CVE-2023-23770CRITICAL Motorola MBTS Site Controller accepts hard-coded backdoor password. The Motorola MBTS Site Controller Man Machine Interface (MMI), allowing for service technicians to diagnose and | Aug 29, 2023 | 9.8 | 28 | NO | NO |
CVE-2025-59817HIGH This vulnerability allows attackers to execute arbitrary commands on the underlying system. Because the web portal runs with root privileges, successful exploitation grants full co | Sep 25, 2025 | 8.4 | 27 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA39 CVEs
18%
59%
23%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local7 (17.9%)
Network21 (53.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network11 (28.2%)
Attack Complexity
Low35 (89.7%)
High4 (10.3%)
Unknown0 (0.0%)
User Interaction
None37 (94.9%)
Unknown0 (0.0%)
Required2 (5.1%)
Privileges Required
Low10 (25.6%)
High5 (12.8%)
None24 (61.5%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (39 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by National Cyber Security Centre Netherlands (NCSC-NL) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by National Cyber Security Centre Netherlands (NCSC-NL) as a CNA — matched by CVE ID, not by organization name.