SBA Research gGmbH

First CVE: Jun 6, 2024Active for: 2 years
11
CVEs Published
More CVEs Published than 28% of tracked CNAs
3.7
Avg CVEs / Year
More Avg CVEs / Year than 27% of tracked CNAs
6.7
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by SBA Research gGmbH over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 6, 2024
2 years ago
Most Recent CVE
Jul 1, 2026
23 days ago

Top CVEs

All CVEs published by SBA Research gGmbH as a CNA, regardless of affected vendor or product.

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate privileges to root or install untrus
Jun 3, 20267.331NONO
LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the service-level authentication of the RAG API.
Mar 18, 20268.025NONO
The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption keys in its HTTP responses to users with the “Service” or “Adm
Jul 1, 20264.324NONO
The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.
Jun 6, 20248.123NONO
Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store o
Jun 25, 20258.022NONO
The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error
Mar 10, 20256.122NONO
The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode erro
Mar 10, 20256.122NONO
Cyberduck and Mountain Duck improper handle TLS certificate pinning for untrusted certificates (e.g., self-signed), since the certificate fingerprint is stored as SHA-1, although S
Jun 25, 20257.421NONO
Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting this flaw combined with other vulnerabilities can lead to una
Mar 4, 20264.820NONO
The Paradox IP150 Internet Module in version 1.40.00 is vulnerable to Cross-Site Request Forgery (CSRF) attacks due to a lack of countermeasures and the use of the HTTP method `GET
Jun 19, 20246.820NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA11 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHigh
Attack Vector
Local1 (9.1%)
Network9 (81.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (9.1%)
Attack Complexity
Low6 (54.5%)
High5 (45.5%)
Unknown0 (0.0%)
User Interaction
None7 (63.6%)
Unknown0 (0.0%)
Required4 (36.4%)
Privileges Required
Low4 (36.4%)
High0 (0.0%)
None7 (63.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by SBA Research gGmbH as a CNA.

Media Mentions

Media articles that mention a CVE ID published by SBA Research gGmbH as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs