Security Risk Advisors (SRA)

First CVE: Feb 19, 2024Active for: 2 years
14
CVEs Published
More CVEs Published than 34% of tracked CNAs
4.7
Avg CVEs / Year
More Avg CVEs / Year than 31% of tracked CNAs
7.4
Avg CVSS Score
Higher Avg CVSS Score than 62% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by Security Risk Advisors (SRA) over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 19, 2024
2 years ago
Most Recent CVE
Jul 20, 2026
4 days ago

Top CVEs

All CVEs published by Security Risk Advisors (SRA) as a CNA, regardless of affected vendor or product.

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and dire
Jul 17, 20269.338NONO
VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these respo
Jul 20, 20269.036NONO
An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly sanitize the p
Jul 17, 20268.635NONO
VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'r
Jul 20, 20268.733NONO
A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality. The submit_modify_v
Jul 17, 20267.029NONO
An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through the soun
Jul 17, 20267.129NONO
Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows decryption of document archive files
Jan 20, 20267.528NONO
Insufficiently Protected Credentials vulnerability in the Credential Field of Milner ImageDirector Capture allows retrieval of credential material and enables database access.This
Jan 20, 20267.528NONO
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Brivo ACS100, ACS300 allows OS Command Injection, Bypassing Physical Sec
Feb 19, 20248.825NONO
Use of a Broken or Risky Cryptographic Algorithm (DES) vulnerability in the Password class in C2SConnections.dll in Milner ImageDirector Capture on Windows allows Encryption Brut
Jan 20, 20267.524NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA14 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local1 (7.1%)
Network11 (78.6%)
Unknown0 (0.0%)
Physical1 (7.1%)
Adjacent Network1 (7.1%)
Attack Complexity
Low13 (92.9%)
High1 (7.1%)
Unknown0 (0.0%)
User Interaction
None12 (85.7%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (28.6%)
High0 (0.0%)
None10 (71.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Security Risk Advisors (SRA) as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Security Risk Advisors (SRA) as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs