certcc
CVE Numbering Authority
Latest CVE published
Overview
certcc is a CVE Numbering Authority that has published 2,972 CVE records since 2005. It is currently classified as active, with 85 CVEs published in the last two years. Its CVE data quality is graded F (10.6% overall completeness).
Among the 370 CNAs tracked here, certcc ranks #20 by CVE volume and reports more complete records than 1% of all CNAs.
Data quality report card
How complete and consistent certcc's CVE records are, scored across vendor, product, CVSS, and CWE coverage.
A CVE record only requires a description to be published. “Completeness” measures how often certcc also fills in the optional — but extremely useful — fields that make a vulnerability actually actionable: the affected vendor and product, a CVSS severity score, and a CWE weakness type. A higher score means more of this CNA’s CVEs include those details, so defenders spend less time enriching records by hand.
Report card grade
10.6%
Overall score
What these scores mean
- Vendor completeness
- The share of this CNA's CVEs that name an affected vendor.
- Product completeness
- The share that name a specific affected product.
- CVSS completeness
- The share that include a CVSS severity score.
- CWE completeness
- The share mapped to a CWE weakness type.
- Update rate
- How often this CNA revises CVE records after first publishing them.
- Vendor diversity
- How many distinct vendors this CNA publishes CVEs for.
Severity and exploitation
How the CVSS severity of certcc's published CVEs breaks down, and how many are known to be exploited in the wild.
1 additional CVE has no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
7
7 of certcc's CVEs are confirmed exploited in the wild and carry a CISA remediation deadline.
Common weakness types
The CWE weakness categories certcc most often assigns to its CVEs. Follow any weakness to its full explanation.
- CWE-502Deserialization of Untrusted Data16 CVEs
- CWE-306Missing Authentication for Critical Function15 CVEs
- CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')14 CVEs
- CWE-798Use of Hard-coded Credentials14 CVEs
- CWE-400Uncontrolled Resource Consumption13 CVEs
- CWE-284Improper Access Control11 CVEs
- CWE-3109 CVEs
- CWE-295Improper Certificate Validation9 CVEs
Publishing activity by year
How many CVEs certcc has published each year.
Top vendors
The vendors certcc publishes the most CVEs for.
Top products
The products certcc publishes the most CVEs for.
- debian linux76 CVEs
- ubuntu linux54 CVEs
- fedora26 CVEs
- leap26 CVEs
- enterprise linux server23 CVEs
- LSI Storage Authority (LSA)22 CVEs
- raid controller web interface22 CVEs
- freebsd21 CVEs
Latest CVEs
The most recent CVEs assigned by certcc.
- CVE-2026-80047
Hugging Face Transformers library writes remote code to disk prior to consent check
Unscored2026-09-01 - CVE-2026-19913CWE-20
CVE-2026-19913
High · CVSS 7.5EPSS 0.4%2026-08-25 - CVE-2026-19912CWE-20
CVE-2026-19912
Critical · CVSS 9.8EPSS 0.2%2026-08-25 - CVE-2026-19874CWE-122
Konami's Metal Gear Online 3 contains a heap-based buffer overflow
Critical · CVSS 9.1EPSS 0.7%2026-08-24 - CVE-2026-75501CWE-306
CVE-2026-75501
High · CVSS 7.5EPSS 0.6%2026-08-21 - CVE-2026-18482CWE-78
CVE-2026-18482
Critical · CVSS 9.8EPSS 1.7%2026-08-20 - CVE-2026-19508CWE-119
RDK WebUI heap-based buffer overflow vulnerability
Critical · CVSS 9.8EPSS 0.8%2026-08-19 - CVE-2026-19509CWE-20
RDK WebUI DOS vulnerability
Medium · CVSS 6.5EPSS 0.3%2026-08-19 - CVE-2026-19507CWE-400
RDK WebUI uncontrolled resource consumption
High · CVSS 7.5EPSS 0.4%2026-08-19 - CVE-2026-19506CWE-362
RDK-B WebUI race condition vulnerability
High · CVSS 8.1EPSS 0.4%2026-08-19 - CVE-2026-19505CWE-347
RDK-B WebUI improper cryptographic signature verification vulnerability
Critical · CVSS 9.8EPSS 0.4%2026-08-19 - CVE-2026-76647CWE-862
Leantime JSON-RPC API contains a missing authorization vulnerability
High · CVSS 8.8EPSS 0.4%2026-08-19
Track new certcc CVEs as they are published and get AI-written analysis and remediation guidance.
Monitor certcc CVEsOther CNAs
Compare data quality across other CVE Numbering Authorities.
Frequently asked questions
Common questions about the certcc CNA.
- What is the certcc CNA?
- certcc is a CVE Numbering Authority (CNA) — an organization authorized to assign CVE IDs to vulnerabilities in its scope. It has published 2,972 CVE records since 2005.
- How many CVEs has certcc published?
- certcc has published 2,972 CVE records, including 85 in the last two years.
- What is certcc's CVE data quality grade?
- RadicalNotion.AI grades certcc's CVE data quality as F, with an overall completeness score of 10.6%. This reflects how consistently its CVE records include vendor (14.5%), product (16.9%), CVSS (1.9%), and CWE (9.2%) information.
- What products does certcc publish CVEs for?
- certcc most frequently publishes CVEs for debian linux, ubuntu linux, fedora, leap, enterprise linux server.
- Which vendors does certcc cover?
- certcc publishes CVEs across 232 distinct vendors, most often debian, canonical, Microsoft Corporation, magzter, Red Hat.
- Is certcc actively publishing CVEs?
- certcc is currently active, based on 85 CVEs in the last two years.
- What is the average severity of certcc's CVEs?
- The average CVSS base score across certcc's scored CVEs is 7.4.
- How many critical CVEs has certcc published?
- certcc has published 453 critical-severity CVEs and 580 high-severity CVEs.
- Are any of certcc's CVEs in CISA's Known Exploited Vulnerabilities catalog?
- Yes. 7 of certcc's CVEs are listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, meaning they are confirmed to be exploited in the wild.
- What are the most common weakness types in certcc's CVEs?
- certcc's CVEs most often map to these CWE weakness types: CWE-502 (Deserialization of Untrusted Data), CWE-306 (Missing Authentication for Critical Function), CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-798 (Use of Hard-coded Credentials).
- How does certcc rank among CNAs?
- By total CVE volume, certcc ranks #20 of 370 CNAs, and it reports more complete CVE records than 1% of all CNAs.
References
- Official CVE.org list of CNA partners (opens in a new tab)
- Learn: What is a CNA?
- CWE directory: the weakness types this CNA maps its CVEs to
CNA report-card grades are computed by RadicalNotion.AI from published CVE records. CVE data is sourced from the CVE Program.
Track certcc CVEs
Monitor new vulnerabilities as this CNA publishes them, with AI-written analysis and remediation guidance.