VulDB
First CVE: Mar 28, 2022Active for: 4 years
15,358
CVEs Published
More CVEs Published than 99% of tracked CNAs
3071.6
Avg CVEs / Year
More Avg CVEs / Year than 100% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 71% of tracked CNAs
0.0%
In CISA KEV
Higher KEV Rate than 77% of tracked CNAs
Trends Over Time
The number and severity of CVEs published by VulDB over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 28, 2022
4 years ago
Most Recent CVE
Jul 23, 2026
1 day ago
Top CVEs
All CVEs published by VulDB as a CNA, regardless of affected vendor or product.
15,358 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-3273CRITICAL ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unkno | Apr 4, 2024 | 9.8 | 98 | YES | YES |
CVE-2024-12987CRITICAL A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcf | Dec 27, 2024 | 9.8 | 97 | YES | YES |
CVE-2024-3272CRITICAL ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue | Apr 4, 2024 | 9.8 | 97 | YES | YES |
CVE-2024-0769CRITICAL ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file | Jan 21, 2024 | 9.8 | 95 | YES | NO |
CVE-2024-10914CRITICAL A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is the function cgi_us | Nov 6, 2024 | 9.8 | 88 | NO | YES |
CVE-2024-7120CRITICAL A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. This affects an unknown part of the file list_base_config.php | Jul 26, 2024 | 9.8 | 87 | NO | YES |
CVE-2023-6895CRITICAL A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been declared as critical. This vulnerability affects unknown code of the fi | Dec 17, 2023 | 9.8 | 85 | NO | YES |
CVE-2023-5222CRITICAL A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0. This vulnerability affects the function isValidUser of the file /cgi-bin/vitogate.cgi of t | Sep 27, 2023 | 9.8 | 85 | NO | YES |
CVE-2023-3643CRITICAL A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the | Jul 12, 2023 | 9.8 | 85 | NO | YES |
CVE-2022-2487CRITICAL A vulnerability has been found in WAVLINK WN535K2 and WN535K3 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/nightled.cgi. The manipulatio | Jul 20, 2022 | 9.8 | 83 | NO | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA15,358 CVEs
33%
32%
29%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCriticalUnknown
Attack Vector
Local987 (6.4%)
Network14,106 (91.8%)
Unknown4 (0.0%)
Physical50 (0.3%)
Adjacent Network211 (1.4%)
Attack Complexity
Low14,734 (95.9%)
High620 (4.0%)
Unknown4 (0.0%)
User Interaction
None12,349 (80.4%)
Unknown4 (0.0%)
Required3,005 (19.6%)
Privileges Required
Low6,012 (39.1%)
High1,064 (6.9%)
None8,278 (53.9%)
Unknown4 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (15358 CVEs).
CISA KEV
4 CVEs
0.0% of CVEs· 77th percentile
Metasploit
7 CVEs
0.0% of CVEs· 77th percentile
Nuclei
109 CVEs
0.7% of CVEs· 78th percentile
ExploitDB
77 CVEs
0.5% of CVEs· 77th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by VulDB as a CNA.
Media Mentions
Media articles that mention a CVE ID published by VulDB as a CNA — matched by CVE ID, not by organization name.