NEC Corporation
First CVE: Jun 7, 2021Active for: 5 years
66
CVEs Published
More CVEs Published than 64% of tracked CNAs
11.0
Avg CVEs / Year
More Avg CVEs / Year than 55% of tracked CNAs
8.2
Avg CVSS Score
Higher Avg CVSS Score than 90% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by NEC Corporation as a CNA, 63.6% affect products that NEC Corporation develops as a vendor.
63.6%
36.4%
Self-reported: 42Third-party: 24
Of all the CVEs published that affect products developed by NEC Corporation, 34.4% are self-published by NEC Corporation as a CNA.
34.4%
65.6%
Self-published: 42Published by other CNAs: 80
Trends Over Time
The number and severity of CVEs published by NEC Corporation over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 7, 2021
5 years ago
Most Recent CVE
Jun 26, 2026
28 days ago
Top CVEs
All CVEs published by NEC Corporation as a CNA, regardless of affected vendor or product.
66 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-8797HIGH An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM | Jun 26, 2026 | 8.5 | 37 | NO | NO |
CVE-2026-4620CRITICAL OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network. | Mar 27, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-4622CRITICAL OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network. | Mar 27, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-4619CRITICAL Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network. | Mar 27, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-8652HIGH An OS Command Injection vulnerability exists in Aterm. If a malicious third person gains administrator access to the product’s web console, they may be able to execute arbitrary OS | May 25, 2026 | 8.5 | 34 | NO | NO |
CVE-2025-12049CRITICAL Missing Authentication for Critical Function vulnerability in Sharp Display Solutions Media Player MP-01 All Verisons allows a attacker may access to the web interface of the affec | Dec 22, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-11543CRITICAL Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthorized firmware. | Dec 22, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-11542CRITICAL Stack-based Buffer Overflow vulnerability in Sharp Display Solutions projectors allows a attacker may execute arbitrary commands and programs. | Dec 22, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-11541CRITICAL Stack-based Buffer Overflow vulnerability in Sharp Display Solutions projectors allows a attacker may execute arbitrary commands and programs. | Dec 22, 2025 | 9.8 | 34 | NO | NO |
CVE-2021-20701CRITICAL Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Window | Nov 3, 2021 | 9.8 | 31 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA66 CVEs
24%
26%
50%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (4.5%)
Network60 (90.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.5%)
Attack Complexity
Low65 (98.5%)
High1 (1.5%)
Unknown0 (0.0%)
User Interaction
None60 (90.9%)
Unknown0 (0.0%)
Required3 (4.5%)
Privileges Required
Low9 (13.6%)
High8 (12.1%)
None49 (74.2%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (66 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by NEC Corporation as a CNA.
Media Mentions
Media articles that mention a CVE ID published by NEC Corporation as a CNA — matched by CVE ID, not by organization name.