TWCERT/CC

First CVE: Feb 11, 2019Active for: 7 years
881
CVEs Published
More CVEs Published than 90% of tracked CNAs
110.1
Avg CVEs / Year
More Avg CVEs / Year than 90% of tracked CNAs
7.7
Avg CVSS Score
Higher Avg CVSS Score than 79% of tracked CNAs
0.3%
In CISA KEV
Higher KEV Rate than 83% of tracked CNAs

Trends Over Time

The number and severity of CVEs published by TWCERT/CC over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 11, 2019
7 years ago
Most Recent CVE
Jul 15, 2026
9 days ago

Top CVEs

All CVEs published by TWCERT/CC as a CNA, regardless of affected vendor or product.

881 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system com
Nov 15, 20249.882YESNO
ECOA BAS controller suffers from a path traversal content disclosure vulnerability. Using the GET parameter in File Manager, unauthenticated attackers can remotely disclose directo
Sep 30, 20217.577NOYES
Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execu
Jun 17, 20249.875YESNO
Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.
Jun 14, 20249.868NOYES
ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload
Aug 12, 20247.264YESNO
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by directly using input as a format string when calling syslog in logme
Jul 21, 20237.244NONO
ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files disclosure. Using the specific POST parameter, unauthenticated attackers can remotely discl
Sep 30, 20217.544NOYES
Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API doc
Jun 30, 20269.842NONO
Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obta
Jul 6, 20269.841NONO
ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view application code and obtain the databas
Jul 6, 20269.841NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA881 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local24 (2.7%)
Network812 (92.2%)
Unknown0 (0.0%)
Physical15 (1.7%)
Adjacent Network30 (3.4%)
Attack Complexity
Low875 (99.3%)
High6 (0.7%)
Unknown0 (0.0%)
User Interaction
None761 (86.4%)
Unknown0 (0.0%)
Required119 (13.5%)
Privileges Required
Low225 (25.5%)
High115 (13.1%)
None541 (61.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (881 CVEs).

CISA KEV
3 CVEs
0.3% of CVEs· 83rd percentile
Metasploit
2 CVEs
0.2% of CVEs· 79th percentile
Nuclei
4 CVEs
0.5% of CVEs· 75th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by TWCERT/CC as a CNA.

Media Mentions

Media articles that mention a CVE ID published by TWCERT/CC as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs