Vulnerability Management
Firmware- and protocol-aware CVE correlation, ranked by real exploitability on your fleet.
Critical
2
High
3
Medium
2
Low
1
| CVE | Finding | Vertical | CVSS | Exploit | Assets | Status | First seen |
|---|---|---|---|---|---|---|---|
| CVE-2025-32118 | Unauthenticated ONVIF command injection VUL-501 | IoT | 9.8 | Weaponized | 34 | Open | 2026-08-14 |
| CVE-2025-11907 | BACnet write without authorization VUL-502 | OT | 9.4 | PoC | 11 | In progress | 2026-08-02 |
| CVE-2024-44081 | Hardcoded maintenance credentials in pump firmware VUL-503 | IoMT | 8.6 | PoC | 7 | Open | 2026-07-21 |
| CVE-2025-20144 | OPC-UA certificate validation bypass VUL-504 | IIoT | 8.1 | None | 9 | In progress | 2026-08-19 |
| CVE-2025-3391 | RTSP stream exposed without credentials VUL-505 | IoT | 7.9 | Weaponized | 22 | Open | 2026-06-30 |
| CVE-2024-9911 | DICOM node accepts unsigned associations VUL-506 | IoMT | 6.4 | None | 4 | Mitigated | 2026-05-12 |
| CVE-2025-1180 | Modbus TCP replay of coil writes VUL-507 | OT | 6.1 | PoC | 15 | Accepted | 2026-04-04 |
| CVE-2025-8842 | Default SNMP community string VUL-508 | IT | 3.9 | None | 41 | Mitigated | 2026-03-18 |