Nozomi
CVE Numbering Authority
Latest CVE published
Overview
Nozomi is a CVE Numbering Authority that has published 229 CVE records since 2021. It is currently classified as active, with 195 CVEs published in the last two years. Its CVE data quality is graded A (99.9% overall completeness).
Among the 370 CNAs tracked here, Nozomi ranks #80 by CVE volume and reports more complete records than 59% of all CNAs.
Data quality report card
How complete and consistent Nozomi's CVE records are, scored across vendor, product, CVSS, and CWE coverage.
A CVE record only requires a description to be published. “Completeness” measures how often Nozomi also fills in the optional — but extremely useful — fields that make a vulnerability actually actionable: the affected vendor and product, a CVSS severity score, and a CWE weakness type. A higher score means more of this CNA’s CVEs include those details, so defenders spend less time enriching records by hand.
Report card grade
99.9%
Overall score
What these scores mean
- Vendor completeness
- The share of this CNA's CVEs that name an affected vendor.
- Product completeness
- The share that name a specific affected product.
- CVSS completeness
- The share that include a CVSS severity score.
- CWE completeness
- The share mapped to a CWE weakness type.
- Update rate
- How often this CNA revises CVE records after first publishing them.
- Vendor diversity
- How many distinct vendors this CNA publishes CVEs for.
Severity and exploitation
How the CVSS severity of Nozomi's published CVEs breaks down, and how many are known to be exploited in the wild.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of Nozomi's CVEs are currently listed in CISA's Known Exploited Vulnerabilities catalog.
Common weakness types
The CWE weakness categories Nozomi most often assigns to its CVEs. Follow any weakness to its full explanation.
- CWE-125Out-of-bounds Read34 CVEs
- CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')33 CVEs
- CWE-306Missing Authentication for Critical Function19 CVEs
- CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')14 CVEs
- CWE-862Missing Authorization12 CVEs
- CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')11 CVEs
- CWE-690Unchecked Return Value to NULL Pointer Dereference9 CVEs
- CWE-787Out-of-bounds Write9 CVEs
Publishing activity by year
How many CVEs Nozomi has published each year.
Top vendors
The vendors Nozomi publishes the most CVEs for.
- Nozomi Networks56 CVEs
- Q-Free43 CVEs
- Open Networking Foundation37 CVEs
- opennetworking37 CVEs
- Advantech20 CVEs
- Siemens17 CVEs
- Waterfall17 CVEs
- waterfall-security17 CVEs
Top products
The products Nozomi publishes the most CVEs for.
- CMC47 CVEs
- Guardian46 CVEs
- MaxTime43 CVEs
- libfluid37 CVEs
- libfluid msg37 CVEs
- EKI-6333AC-2GD20 CVEs
- EKI-6333AC-2G20 CVEs
- eki-6333ac-2gd_firmware20 CVEs
Latest CVEs
The most recent CVEs assigned by Nozomi.
- CVE-2026-57472CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in KUNBUS RevPiPyLoad
Medium · CVSS 6.9EPSS 0.1%2026-08-14 - CVE-2026-57471CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in KUNBUS RevPiPyLoad
Medium · CVSS 6.8EPSS 0.1%2026-08-14 - CVE-2026-57469CWE-352
Cross-Site Request Forgery (CSRF) in KUNBUS PiCtory
Medium · CVSS 5.1EPSS 0.2%2026-08-14 - CVE-2026-13198CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in KUNBUS piControl
Medium · CVSS 5.9EPSS 0.1%2026-08-14 - CVE-2026-13197CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in KUNBUS piControl
High · CVSS 7.3EPSS 0.1%2026-08-14 - CVE-2026-13196CWE-787
Out-of-bounds Write in KUNBUS piControl
High · CVSS 7.3EPSS 0.1%2026-08-14 - CVE-2026-33922CWE-22
Path traversal in the Offline archives functionality of the local web interface in Arc before v2.7.0
Medium · CVSS 6.8EPSS 0.1%2026-08-11 - CVE-2026-33921CWE-1188
Npcap driver installed without administrator-only access restriction on Windows in Arc before v2.7.0
Medium · CVSS 4.8EPSS 0.1%2026-08-11 - CVE-2026-33390CWE-266
Incorrect privilege assignment for Arc sensors in Guardian/CMC before 26.2.0
High · CVSS 7.2EPSS 0.4%2026-07-09 - CVE-2026-31985CWE-671
Disabled and non-configurable TLS certificate validation in n2os-tui when connecting the Remote Collector to a Guardian or CMC, in Remote Collector before v26.2.0
High · CVSS 8.3EPSS 0.2%2026-07-09 - CVE-2026-31984CWE-770
DoS through oversized audit log entries in Guardian/CMC before 26.2.0
High · CVSS 8.7EPSS 0.5%2026-07-09 - CVE-2026-31983CWE-306
Missing authentication in SSH keys synchronization endpoint in Guardian/CMC before 26.2.0
Medium · CVSS 6.9EPSS 0.4%2026-07-09
Track new Nozomi CVEs as they are published and get AI-written analysis and remediation guidance.
Monitor Nozomi CVEsOther CNAs
Compare data quality across other CVE Numbering Authorities.
Frequently asked questions
Common questions about the Nozomi CNA.
- What is the Nozomi CNA?
- Nozomi is a CVE Numbering Authority (CNA) — an organization authorized to assign CVE IDs to vulnerabilities in its scope. It has published 229 CVE records since 2021.
- How many CVEs has Nozomi published?
- Nozomi has published 229 CVE records, including 195 in the last two years.
- What is Nozomi's CVE data quality grade?
- RadicalNotion.AI grades Nozomi's CVE data quality as A, with an overall completeness score of 99.9%. This reflects how consistently its CVE records include vendor (100%), product (100%), CVSS (100%), and CWE (99.6%) information.
- What products does Nozomi publish CVEs for?
- Nozomi most frequently publishes CVEs for CMC, Guardian, MaxTime, libfluid, libfluid msg.
- Which vendors does Nozomi cover?
- Nozomi publishes CVEs across 22 distinct vendors, most often Nozomi Networks, Q-Free, Open Networking Foundation, opennetworking, Advantech.
- Is Nozomi actively publishing CVEs?
- Nozomi is currently active, based on 195 CVEs in the last two years.
- What is the average severity of Nozomi's CVEs?
- The average CVSS base score across Nozomi's scored CVEs is 6.7.
- How many critical CVEs has Nozomi published?
- Nozomi has published 41 critical-severity CVEs and 151 high-severity CVEs.
- Are any of Nozomi's CVEs in CISA's Known Exploited Vulnerabilities catalog?
- No. None of Nozomi's CVEs are currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
- What are the most common weakness types in Nozomi's CVEs?
- Nozomi's CVEs most often map to these CWE weakness types: CWE-125 (Out-of-bounds Read), CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')), CWE-306 (Missing Authentication for Critical Function), CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
- How does Nozomi rank among CNAs?
- By total CVE volume, Nozomi ranks #80 of 370 CNAs, and it reports more complete CVE records than 59% of all CNAs.
References
- Official CVE.org list of CNA partners (opens in a new tab)
- Learn: What is a CNA?
- CWE directory: the weakness types this CNA maps its CVEs to
CNA report-card grades are computed by RadicalNotion.AI from published CVE records. CVE data is sourced from the CVE Program.
Track Nozomi CVEs
Monitor new vulnerabilities as this CNA publishes them, with AI-written analysis and remediation guidance.