Wiz, Inc.
First CVE: Oct 1, 2024Active for: 2 years
7
CVEs Published
More CVEs Published than 20% of tracked CNAs
3.5
Avg CVEs / Year
More Avg CVEs / Year than 25% of tracked CNAs
8.3
Avg CVSS Score
Higher Avg CVSS Score than 91% of tracked CNAs
28.6%
In CISA KEV
Higher KEV Rate than 100% of tracked CNAs
Trends Over Time
The number and severity of CVEs published by Wiz, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 1, 2024
21 months ago
Most Recent CVE
Dec 10, 2025
226 days ago
Top CVEs
All CVEs published by Wiz, Inc. as a CNA, regardless of affected vendor or product.
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8110HIGH Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code. | Dec 10, 2025 | 8.8 | 96 | YES | YES |
CVE-2025-53690CRITICAL Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager ( | Sep 3, 2025 | 9.0 | 85 | YES | NO |
CVE-2025-53693CRITICAL Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) all | Sep 3, 2025 | 9.8 | 40 | NO | NO |
CVE-2025-53691HIGH Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (RCE).This issue affects Experie | Sep 3, 2025 | 8.8 | 30 | NO | NO |
CVE-2025-53694HIGH Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP).This issue affects Sitecore | Sep 3, 2025 | 7.5 | 28 | NO | NO |
CVE-2025-53692HIGH Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform | Sep 21, 2025 | 7.1 | 24 | NO | NO |
CVE-2024-9145HIGH Wiz Code Visual Studio Code extension in versions 1.0.0 up to 1.5.3 and Wiz (legacy) Visual Studio Code extension in versions 0.13.0 up to 0.17.8 are vulnerable to local command in | Oct 1, 2024 | 7.1 | 20 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA7 CVEs
71%
29%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local1 (14.3%)
Network6 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (85.7%)
High1 (14.3%)
Unknown0 (0.0%)
User Interaction
None5 (71.4%)
Unknown0 (0.0%)
Required1 (14.3%)
Privileges Required
Low2 (28.6%)
High0 (0.0%)
None5 (71.4%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (7 CVEs).
CISA KEV
2 CVEs
28.6% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
14.3% of CVEs· 99th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Wiz, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Wiz, Inc. as a CNA — matched by CVE ID, not by organization name.