BL Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for BL products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
9
In CISA KEV
3
Beyond CISA KEV
6
Sensor Observed
0
Virtual Patch Available
0
BL KEVs Added by Year
9 BL KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-9316
N-central unauthenticated sessionID generation |
N-central | High | Not in CISA | 03 Jun 2026 |
|
CVE-2020-35580
A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated users to read arbitrary files... |
SearchBlox | High | Not in CISA | 14 Jul 2025 |
|
CVE-2025-8876
Command Injection Vulnerability |
N-central | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-8875
Insecure Deserialization Vulnerability |
N-central | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-45988
Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4... |
Blink routers | High | Not in CISA | 13 Jun 2025 |
|
CVE-2025-32814
An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur. |
NETMRI | High | Not in CISA | 22 May 2025 |
|
CVE-2025-0994
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization... |
Cityworks, Cityworks (with office companion) | Confirmed | In CISA | 07 Feb 2025 |
|
CVE-2025-29063
An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to... |
AC2100 | High | Not in CISA | 02 Apr 2025 |
|
CVE-2022-32409
A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers... |
i3geo | High | Not in CISA | 14 Jul 2022 |
Common Vulnerability Classes (CWE)
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
- CWE-502 — Deserialization of Untrusted Data 2
- CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 2
- CWE-1284 — Improper Validation of Specified Quantity in Input 1
- CWE-20 — Improper Input Validation 1
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology