Nationalkeep maintains a narrow product portfolio centered on the CyberMath application, a security-focused tool whose vulnerability surface skews strongly toward critical-severity outcomes. The recurring weakness classes—cross-site scripting, cross-site request forgery, improper file access controls, authorization flaws, and unrestricted file uploads—point to persistent web application and access-control deficiencies typical of applications handling sensitive security operations. Defenders relying on this product should prioritize patches for critical disclosures and verify proper isolation and authentication controls; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nationalkeep over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7108CRITICAL Incorrect Authorization vulnerability in National Keep Cyber Security Services CyberMath allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects CyberM | Sep 26, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-6675CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in National Keep Cyber Security Services CyberMath allows Upload a Web Shell to a Web Server.
This issue affects Cybe | Feb 2, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-6676HIGH Cross-Site Request Forgery (CSRF) vulnerability in National Keep Cyber Security Services CyberMath allows Cross Site Request Forgery.
This issue affects CyberMath: from v1.4 befor | Feb 2, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-7107HIGH Files or Directories Accessible to External Parties vulnerability in National Keep Cyber Security Services CyberMath allows Collect Data from Common Resource Locations.
This issue | Sep 26, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-6673MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in National Keep Cyber Security Services CyberMath allows Reflected XSS.
This is | Feb 2, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-6672MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in National Keep Cyber Security Services CyberMath allows Stored XSS.
This issue | Feb 2, 2024 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nationalkeep.
Media articles that mention a CVE ID that affects a product developed by Nationalkeep — matched by CVE ID, not by vendor name.