BL Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for BL products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

9

In CISA KEV

3

Beyond CISA KEV

6

Sensor Observed

0

Virtual Patch Available

0

BL KEVs Added by Year

Loading...

9 BL KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2025-9316

N-central unauthenticated sessionID generation

High Not in CISA 03 Jun 2026
CVE-2020-35580

A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated users to read arbitrary files...

High Not in CISA 14 Jul 2025
CVE-2025-8876

Command Injection Vulnerability

Confirmed In CISA 01 Jun 2026
CVE-2025-8875

Insecure Deserialization Vulnerability

Confirmed In CISA 01 Jun 2026
CVE-2025-45988

Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4...

High Not in CISA 13 Jun 2025
CVE-2025-32814

An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.

High Not in CISA 22 May 2025
CVE-2025-0994

Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization...

Confirmed In CISA 07 Feb 2025
CVE-2025-29063

An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to...

High Not in CISA 02 Apr 2025
CVE-2022-32409

A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers...

High Not in CISA 14 Jul 2022

Common Vulnerability Classes (CWE)

  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
  • CWE-502 — Deserialization of Untrusted Data 2
  • CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 2
  • CWE-1284 — Improper Validation of Specified Quantity in Input 1
  • CWE-20 — Improper Input Validation 1
  • CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology