SEC Consult Vulnerability Lab

First CVE: Nov 22, 2023Active for: 3 years
126
CVEs Published
More CVEs Published than 73% of tracked CNAs
31.5
Avg CVEs / Year
More Avg CVEs / Year than 77% of tracked CNAs
7.3
Avg CVSS Score
Higher Avg CVSS Score than 59% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by SEC Consult Vulnerability Lab over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 22, 2023
2 years ago
Most Recent CVE
Jun 18, 2026
36 days ago

Top CVEs

All CVEs published by SEC Consult Vulnerability Lab as a CNA, regardless of affected vendor or product.

126 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers
Jun 12, 20256.149NOYES
HYDRA X, MIP 2 and FEDRA 2 of MPDV Mikrolab GmbH suffer from an unauthenticated local file disclosure vulnerability in all releases until Maintenance Pack 36 with Servicepack 8 (we
Oct 27, 20257.542NOYES
Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps client application binaries. The exposed credentials include
Jun 18, 20269.336NONO
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains missing authorization checks on multiple web application endpoints. An authenticated attacker with m
Jun 15, 20268.633NONO
The web server of Lawo AG vsm LTC Time Sync (vTimeSync) is affected by a "..." (triple dot) path traversal vulnerability. By sending a specially crafted HTTP request, an unauthenti
Oct 24, 20247.533NOYES
syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vulnerability. An attacker with valid credentials for a user a
Jun 16, 20268.732NONO
The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485 communication between the server and the microcontroller without cryptographic prot
Jun 15, 20268.632NONO
Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.pr
Jun 10, 20268.432NONO
Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.pr
Jun 10, 20268.432NONO
Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC client component included with the product is signed with h
Jun 9, 20267.832NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA126 CVEs
Severity distribution among all CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local34 (27.0%)
Network81 (64.3%)
Unknown0 (0.0%)
Physical9 (7.1%)
Adjacent Network0 (0.0%)
Attack Complexity
Low118 (93.7%)
High8 (6.3%)
Unknown0 (0.0%)
User Interaction
None104 (82.5%)
Unknown0 (0.0%)
Required18 (14.3%)
Privileges Required
Low40 (31.7%)
High12 (9.5%)
None74 (58.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (126 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
2.4% of CVEs· 87th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by SEC Consult Vulnerability Lab as a CNA.

Media Mentions

Media articles that mention a CVE ID published by SEC Consult Vulnerability Lab as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs