The number and severity of CVEs published that impact products developed by Navtor over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-21404MEDIUM NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If the SOAP functionality is enabled, a l | Jun 4, 2026 | 6.3 | 28 | NO | NO |
CVE-2026-2754HIGH Navtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints. An unauthenticated remote attacker with network access to th | Mar 6, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-2753HIGH An Absolute Path Traversal vulnerability exists in Navtor NavBox. The application exposes an HTTP service that fails to properly sanitize user-supplied path input. Unauthenticated | Mar 6, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-2752MEDIUM Navtor NavBox allows information disclosure via the /api/ais-data endpoint. A remote, unauthenticated attacker can send crafted requests to trigger an unhandled exception, causing | Mar 6, 2026 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Navtor.
Media articles that mention a CVE ID that affects a product developed by Navtor — matched by CVE ID, not by vendor name.