Security Risk Advisors (SRA)
First CVE: Feb 19, 2024Active for: 2 years
14
CVEs Published
More CVEs Published than 34% of tracked CNAs
4.7
Avg CVEs / Year
More Avg CVEs / Year than 31% of tracked CNAs
7.4
Avg CVSS Score
Higher Avg CVSS Score than 62% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Security Risk Advisors (SRA) over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 19, 2024
2 years ago
Most Recent CVE
Jul 20, 2026
4 days ago
Top CVEs
All CVEs published by Security Risk Advisors (SRA) as a CNA, regardless of affected vendor or product.
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-9586CRITICAL An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and dire | Jul 17, 2026 | 9.3 | 38 | NO | NO |
CVE-2026-13380CRITICAL VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these respo | Jul 20, 2026 | 9.0 | 36 | NO | NO |
CVE-2026-9585HIGH An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly sanitize the p | Jul 17, 2026 | 8.6 | 35 | NO | NO |
CVE-2026-13381HIGH VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'r | Jul 20, 2026 | 8.7 | 33 | NO | NO |
CVE-2026-9588HIGH A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality. The submit_modify_v | Jul 17, 2026 | 7.0 | 29 | NO | NO |
CVE-2026-9587HIGH An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through the soun | Jul 17, 2026 | 7.1 | 29 | NO | NO |
CVE-2025-58744HIGH Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSettings.dll in
Milner ImageDirector Capture on Windows allows decryption of document archive files | Jan 20, 2026 | 7.5 | 28 | NO | NO |
CVE-2025-58741HIGH Insufficiently Protected Credentials vulnerability in the Credential Field of Milner ImageDirector Capture allows retrieval of credential material and enables database access.This | Jan 20, 2026 | 7.5 | 28 | NO | NO |
CVE-2023-6260HIGH Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Brivo ACS100, ACS300 allows OS Command Injection, Bypassing Physical Sec | Feb 19, 2024 | 8.8 | 25 | NO | NO |
CVE-2025-58743HIGH Use of a Broken or Risky Cryptographic Algorithm (DES) vulnerability
in the Password class in C2SConnections.dll in Milner ImageDirector Capture on Windows allows Encryption Brut | Jan 20, 2026 | 7.5 | 24 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA14 CVEs
29%
57%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (7.1%)
Network11 (78.6%)
Unknown0 (0.0%)
Physical1 (7.1%)
Adjacent Network1 (7.1%)
Attack Complexity
Low13 (92.9%)
High1 (7.1%)
Unknown0 (0.0%)
User Interaction
None12 (85.7%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (28.6%)
High0 (0.0%)
None10 (71.4%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Security Risk Advisors (SRA) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Security Risk Advisors (SRA) as a CNA — matched by CVE ID, not by organization name.