SEC Consult Vulnerability Lab
First CVE: Nov 22, 2023Active for: 3 years
126
CVEs Published
More CVEs Published than 73% of tracked CNAs
31.5
Avg CVEs / Year
More Avg CVEs / Year than 77% of tracked CNAs
7.3
Avg CVSS Score
Higher Avg CVSS Score than 59% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by SEC Consult Vulnerability Lab over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 22, 2023
2 years ago
Most Recent CVE
Jun 18, 2026
36 days ago
Top CVEs
All CVEs published by SEC Consult Vulnerability Lab as a CNA, regardless of affected vendor or product.
126 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-5301MEDIUM ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers | Jun 12, 2025 | 6.1 | 49 | NO | YES |
CVE-2025-12055HIGH HYDRA X, MIP 2 and FEDRA 2 of MPDV Mikrolab GmbH suffer from an unauthenticated local file disclosure vulnerability in all releases until Maintenance Pack 36 with Servicepack 8 (we | Oct 27, 2025 | 7.5 | 42 | NO | YES |
CVE-2025-10560CRITICAL Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps client application binaries. The exposed credentials include | Jun 18, 2026 | 9.3 | 36 | NO | NO |
CVE-2026-34024HIGH The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains missing authorization checks on multiple web application endpoints. An authenticated attacker with m | Jun 15, 2026 | 8.6 | 33 | NO | NO |
CVE-2024-6049HIGH The web server of Lawo AG vsm LTC Time Sync (vTimeSync) is affected by a "..." (triple dot) path traversal vulnerability. By sending a specially crafted HTTP request, an unauthenti | Oct 24, 2024 | 7.5 | 33 | NO | YES |
CVE-2026-12225HIGH syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vulnerability. An attacker with valid credentials for a user a | Jun 16, 2026 | 8.7 | 32 | NO | NO |
CVE-2026-34021HIGH The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485 communication between the server and the microcontroller without cryptographic prot | Jun 15, 2026 | 8.6 | 32 | NO | NO |
CVE-2026-24067HIGH Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.pr | Jun 10, 2026 | 8.4 | 32 | NO | NO |
CVE-2026-24066HIGH Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.pr | Jun 10, 2026 | 8.4 | 32 | NO | NO |
CVE-2026-24064HIGH Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC client component included with the product is signed with h | Jun 9, 2026 | 7.8 | 32 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA126 CVEs
42%
43%
15%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local34 (27.0%)
Network81 (64.3%)
Unknown0 (0.0%)
Physical9 (7.1%)
Adjacent Network0 (0.0%)
Attack Complexity
Low118 (93.7%)
High8 (6.3%)
Unknown0 (0.0%)
User Interaction
None104 (82.5%)
Unknown0 (0.0%)
Required18 (14.3%)
Privileges Required
Low40 (31.7%)
High12 (9.5%)
None74 (58.7%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (126 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
2.4% of CVEs· 87th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by SEC Consult Vulnerability Lab as a CNA.
Media Mentions
Media articles that mention a CVE ID published by SEC Consult Vulnerability Lab as a CNA — matched by CVE ID, not by organization name.