Toreon
First CVE: Jul 3, 2025Active for: 1 year
8
CVEs Published
More CVEs Published than 22% of tracked CNAs
4.0
Avg CVEs / Year
More Avg CVEs / Year than 27% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 69% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Toreon over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 3, 2025
12 months ago
Most Recent CVE
Jun 18, 2026
36 days ago
Top CVEs
All CVEs published by Toreon as a CNA, regardless of affected vendor or product.
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-12642CRITICAL lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited to conduct HTTP Header Smuggling attacks.
Successful explo | Nov 3, 2025 | 9.1 | 28 | NO | NO |
CVE-2025-9709HIGH On-Chip Debug and Test Interface With Improper Access Control and Improper Protection against Electromagnetic Fault Injection (EM-FI) in Nordic Semiconductor nRF52810 allow attacke | Sep 5, 2025 | 8.6 | 28 | NO | NO |
CVE-2026-4255HIGH A DLL search order hijacking vulnerability in Thermalright TR-VISION HOME on Windows (64-bit) allows a local attacker to escalate privileges via DLL side-loading. The application l | Mar 16, 2026 | 7.8 | 27 | NO | NO |
CVE-2025-7503CRITICAL An OEM IP camera manufactured by Shenzhen Liandian Communication Technology LTD exposes a Telnet service (port 23) with undocumented, default credentials. The Telnet service is ena | Jul 11, 2025 | 10.0 | 27 | NO | NO |
CVE-2025-7346HIGH Any unauthenticated attacker can bypass the localhost
restrictions posed by the application and utilize this to create
arbitrary packages | Jul 8, 2025 | 8.7 | 24 | NO | NO |
CVE-2026-12527MEDIUM A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmware AppFHE1_V1.0.6.020230803 enables unaut | Jun 18, 2026 | 6.0 | 23 | NO | NO |
CVE-2025-6563MEDIUM A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions below 7.19.2. An attacker can inject the `javascript` protocol in the `dst` parame | Jul 3, 2025 | 4.8 | 22 | NO | YES |
CVE-2025-7202MEDIUM A Cross-Site Request Forgery (CSRF) in Elgato's Key Lights and related light products allows an attacker to host a malicious webpage that remotely controlles the victim's lights. | Aug 6, 2025 | 5.1 | 20 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA8 CVEs
38%
38%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (12.5%)
Network4 (50.0%)
Unknown0 (0.0%)
Physical1 (12.5%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (62.5%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (100.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
12.5% of CVEs· 99th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Toreon as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Toreon as a CNA — matched by CVE ID, not by organization name.