What is the INCIBE CNA?
INCIBE is a CVE Numbering Authority (CNA) — an organization authorized to assign CVE IDs to vulnerabilities in its scope. It has published 997 CVE records since 2020.
How many CVEs has INCIBE published?
INCIBE has published 997 CVE records, including 713 in the last two years.
What is INCIBE's CVE data quality grade?
RadicalNotion.AI grades INCIBE's CVE data quality as A, with an overall completeness score of 99.9%. This reflects how consistently its CVE records include vendor (100%), product (100%), CVSS (100%), and CWE (99.6%) information.
What products does INCIBE publish CVEs for?
INCIBE most frequently publishes CVEs for cups easy, Cups Easy (Purchase & Inventory), e-TMS, appRain CMF, apprain.
Which vendors does INCIBE cover?
INCIBE publishes CVEs across 323 distinct vendors, most often ajaysharma, Cups Easy, AndSoft, Janobe, appRain.
Is INCIBE actively publishing CVEs?
INCIBE is currently active, based on 713 CVEs in the last two years.
What is the average severity of INCIBE's CVEs?
The average CVSS base score across INCIBE's scored CVEs is 7.2.
How many critical CVEs has INCIBE published?
INCIBE has published 227 critical-severity CVEs and 349 high-severity CVEs.
Are any of INCIBE's CVEs in CISA's Known Exploited Vulnerabilities catalog?
No. None of INCIBE's CVEs are currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
What are the most common weakness types in INCIBE's CVEs?
INCIBE's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')), CWE-639 (Authorization Bypass Through User-Controlled Key), CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor).
How does INCIBE rank among CNAs?
By total CVE volume, INCIBE ranks #36 of 370 CNAs, and it reports more complete CVE records than 59% of all CNAs.