Turan Security
First CVE: Mar 10, 2026Active for: 1 year
32
CVEs Published
More CVEs Published than 49% of tracked CNAs
32.0
Avg CVEs / Year
More Avg CVEs / Year than 78% of tracked CNAs
8.4
Avg CVSS Score
Higher Avg CVSS Score than 93% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Turan Security over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 10, 2026
4 months ago
Most Recent CVE
Jun 19, 2026
35 days ago
Top CVEs
All CVEs published by Turan Security as a CNA, regardless of affected vendor or product.
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-12183CRITICAL Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration mo | Jun 13, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-54414CRITICAL FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrato | Jun 19, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-54410HIGH nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header() function of the Modbus/TCP server that allows remote unauthenticated attackers to write o | Jun 14, 2026 | 8.6 | 36 | NO | NO |
CVE-2026-55740CRITICAL Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vulnerability in bus_info.php. The bu | Jun 18, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-54413HIGH driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess() function in iso14229.c that allows a remote u | Jun 14, 2026 | 8.2 | 35 | NO | NO |
CVE-2026-54412HIGH LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response() function in src/mqtt.c that allows a re | Jun 14, 2026 | 8.2 | 35 | NO | NO |
CVE-2026-5463CRITICAL Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attackers to inject newline characters into module options such as | Apr 3, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-54419CRITICAL claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1c104212cd62be2bfca21e5) contains multiple unauthenticated SQ | Jun 18, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-55742CRITICAL Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler. In system/admin/admin.rights.php, the rights update | Jun 18, 2026 | 9.6 | 33 | NO | NO |
CVE-2026-55743CRITICAL The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS comman | Jun 17, 2026 | 9.6 | 33 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA32 CVEs
16%
44%
41%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network31 (96.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (3.1%)
Attack Complexity
Low31 (96.9%)
High1 (3.1%)
Unknown0 (0.0%)
User Interaction
None23 (71.9%)
Unknown0 (0.0%)
Required9 (28.1%)
Privileges Required
Low5 (15.6%)
High1 (3.1%)
None26 (81.3%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (32 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Turan Security as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Turan Security as a CNA — matched by CVE ID, not by organization name.