SBA Research gGmbH
First CVE: Jun 6, 2024Active for: 2 years
11
CVEs Published
More CVEs Published than 28% of tracked CNAs
3.7
Avg CVEs / Year
More Avg CVEs / Year than 27% of tracked CNAs
6.7
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by SBA Research gGmbH over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 6, 2024
2 years ago
Most Recent CVE
Jul 1, 2026
23 days ago
Top CVEs
All CVEs published by SBA Research gGmbH as a CNA, regardless of affected vendor or product.
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-41259HIGH SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate privileges to root or install untrus | Jun 3, 2026 | 7.3 | 31 | NO | NO |
CVE-2025-41258HIGH LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the service-level authentication of the RAG API. | Mar 18, 2026 | 8.0 | 25 | NO | NO |
CVE-2026-13211MEDIUM The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption keys in its HTTP responses to users with the “Service” or “Adm | Jul 1, 2026 | 4.3 | 24 | NO | NO |
CVE-2024-5657HIGH The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP. | Jun 6, 2024 | 8.1 | 23 | NO | NO |
CVE-2025-41255HIGH Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store o | Jun 25, 2025 | 8.0 | 22 | NO | NO |
CVE-2024-13919MEDIUM The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error | Mar 10, 2025 | 6.1 | 22 | NO | NO |
CVE-2024-13918MEDIUM The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode erro | Mar 10, 2025 | 6.1 | 22 | NO | NO |
CVE-2025-41256HIGH Cyberduck and Mountain Duck improper handle TLS certificate pinning for untrusted certificates (e.g., self-signed), since the certificate fingerprint is stored as SHA-1, although S | Jun 25, 2025 | 7.4 | 21 | NO | NO |
CVE-2025-41257MEDIUM Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting this flaw combined with other vulnerabilities can lead to una | Mar 4, 2026 | 4.8 | 20 | NO | NO |
CVE-2024-5676MEDIUM The Paradox IP150 Internet Module in version 1.40.00 is vulnerable to Cross-Site Request Forgery (CSRF) attacks due to a lack of countermeasures and the use of the HTTP method `GET | Jun 19, 2024 | 6.8 | 20 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA11 CVEs
55%
45%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (9.1%)
Network9 (81.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (9.1%)
Attack Complexity
Low6 (54.5%)
High5 (45.5%)
Unknown0 (0.0%)
User Interaction
None7 (63.6%)
Unknown0 (0.0%)
Required4 (36.4%)
Privileges Required
Low4 (36.4%)
High0 (0.0%)
None7 (63.6%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by SBA Research gGmbH as a CNA.
Media Mentions
Media articles that mention a CVE ID published by SBA Research gGmbH as a CNA — matched by CVE ID, not by organization name.