TWCERT/CC
First CVE: Feb 11, 2019Active for: 7 years
881
CVEs Published
More CVEs Published than 90% of tracked CNAs
110.1
Avg CVEs / Year
More Avg CVEs / Year than 90% of tracked CNAs
7.7
Avg CVSS Score
Higher Avg CVSS Score than 79% of tracked CNAs
0.3%
In CISA KEV
Higher KEV Rate than 83% of tracked CNAs
Trends Over Time
The number and severity of CVEs published by TWCERT/CC over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 11, 2019
7 years ago
Most Recent CVE
Jul 15, 2026
9 days ago
Top CVEs
All CVEs published by TWCERT/CC as a CNA, regardless of affected vendor or product.
881 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-11120CRITICAL Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system com | Nov 15, 2024 | 9.8 | 82 | YES | NO |
CVE-2021-41291HIGH ECOA BAS controller suffers from a path traversal content disclosure vulnerability. Using the GET parameter in File Manager, unauthenticated attackers can remotely disclose directo | Sep 30, 2021 | 7.5 | 77 | NO | YES |
CVE-2024-6047CRITICAL Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execu | Jun 17, 2024 | 9.8 | 75 | YES | NO |
CVE-2024-3080CRITICAL Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device. | Jun 14, 2024 | 9.8 | 68 | NO | YES |
CVE-2024-7694HIGH ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload | Aug 12, 2024 | 7.2 | 64 | YES | NO |
CVE-2023-35086HIGH
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by directly using input as a format string when calling syslog in logme | Jul 21, 2023 | 7.2 | 44 | NO | NO |
CVE-2021-41293HIGH ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files disclosure. Using the specific POST parameter, unauthenticated attackers can remotely discl | Sep 30, 2021 | 7.5 | 44 | NO | YES |
CVE-2026-14162CRITICAL Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API doc | Jun 30, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-14808CRITICAL Prog
Management System developed by PROG MIS has a Exposure of Sensitive
Information vulnerability, allowing unauthenticated remote attackers to view
a specific page and obta | Jul 6, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-14807CRITICAL ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view application code and obtain the databas | Jul 6, 2026 | 9.8 | 41 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA881 CVEs
32%
38%
29%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local24 (2.7%)
Network812 (92.2%)
Unknown0 (0.0%)
Physical15 (1.7%)
Adjacent Network30 (3.4%)
Attack Complexity
Low875 (99.3%)
High6 (0.7%)
Unknown0 (0.0%)
User Interaction
None761 (86.4%)
Unknown0 (0.0%)
Required119 (13.5%)
Privileges Required
Low225 (25.5%)
High115 (13.1%)
None541 (61.4%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (881 CVEs).
CISA KEV
3 CVEs
0.3% of CVEs· 83rd percentile
Metasploit
2 CVEs
0.2% of CVEs· 79th percentile
Nuclei
4 CVEs
0.5% of CVEs· 75th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by TWCERT/CC as a CNA.
Media Mentions
Media articles that mention a CVE ID published by TWCERT/CC as a CNA — matched by CVE ID, not by organization name.