TR-CERT (Computer Emergency Response Team of the Republic of Türkiye)
First CVE: Sep 18, 2021Active for: 5 years
703
CVEs Published
More CVEs Published than 89% of tracked CNAs
117.2
Avg CVEs / Year
More Avg CVEs / Year than 91% of tracked CNAs
8.0
Avg CVSS Score
Higher Avg CVSS Score than 86% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by TR-CERT (Computer Emergency Response Team of the Republic of Türkiye) over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 18, 2021
4 years ago
Most Recent CVE
Jul 23, 2026
1 day ago
Top CVEs
All CVEs published by TR-CERT (Computer Emergency Response Team of the Republic of Türkiye) as a CNA, regardless of affected vendor or product.
703 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-2624CRITICAL Missing Authentication for Critical Function vulnerability in ePati Cyber Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows Authentication Bypass.
This i | Feb 25, 2026 | 9.8 | 43 | NO | YES |
CVE-2026-1617CRITICAL Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama allows SQL Injec | Jul 21, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-4321CRITICAL Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web Design and Digital Advertising Agency Destekz allows SQL In | Jul 3, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-2395CRITICAL Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL Injectio | Jul 22, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-12692CRITICAL Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass.
This issue affects Enterprise Video Platform: from 3.11.0.0 befor | Jul 17, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-8297CRITICAL Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services In | Jul 17, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-8307CRITICAL Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Injection.
This issue affects Medi | Jul 8, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-5801CRITICAL Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Ltd. Co. SEM-PMP allows Command L | Jul 10, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-2397CRITICAL Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows SQL Injection.
This issue aff | Jul 10, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-4767CRITICAL Missing authentication for critical function vulnerability in TR7 Cyber Defense Inc. WAF-ASP allows Authentication Abuse.
This issue affects WAF-ASP: from v1.0.324.900 before v1 | Jul 2, 2026 | 9.8 | 40 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA703 CVEs
29%
32%
38%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local17 (2.4%)
Network671 (95.4%)
Unknown0 (0.0%)
Physical3 (0.4%)
Adjacent Network12 (1.7%)
Attack Complexity
Low690 (98.2%)
High13 (1.8%)
Unknown0 (0.0%)
User Interaction
None526 (74.8%)
Unknown0 (0.0%)
Required175 (24.9%)
Privileges Required
Low170 (24.2%)
High37 (5.3%)
None496 (70.6%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (703 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
0.1% of CVEs· 71st percentile
ExploitDB
2 CVEs
0.3% of CVEs· 74th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by TR-CERT (Computer Emergency Response Team of the Republic of Türkiye) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by TR-CERT (Computer Emergency Response Team of the Republic of Türkiye) as a CNA — matched by CVE ID, not by organization name.