63moons
63moons Aero: vulnerabilidades y CVE
63moons Aero tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-51561 | Crítica (9.3) | 0.53% | — | 4 nov 2024 | This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by intercepting and manipulating… |
| CVE-2024-51560 | Alta (7.1) | 0.35% | — | 4 nov 2024 | This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint. An authenticated remote attacker could exploit this vulnerability by providing invalid inputs for… |
| CVE-2024-51559 | Alta (7.1) | 0.34% | — | 4 nov 2024 | This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters to gain… |
| CVE-2024-51558 | Crítica (9.3) | 0.57% | — | 4 nov 2024 | This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force… |
| CVE-2024-51557 | Alta (7.1) | 0.47% | — | 4 nov 2024 | This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through… |
| CVE-2024-51556 | Alta (7.1) | 0.21% | — | 4 nov 2024 | This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response. An authenticated remote attacker could exploit this vulnerability by manipulating API input… |