Austin Hackers Anonymous
First CVE: Jun 7, 2023Active for: 3 years
38
CVEs Published
More CVEs Published than 52% of tracked CNAs
9.5
Avg CVEs / Year
More Avg CVEs / Year than 52% of tracked CNAs
7.8
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Austin Hackers Anonymous over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 7, 2023
3 years ago
Most Recent CVE
Jun 24, 2026
30 days ago
Top CVEs
All CVEs published by Austin Hackers Anonymous as a CNA, regardless of affected vendor or product.
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2054CRITICAL The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" us | Mar 21, 2024 | 9.8 | 87 | NO | YES |
CVE-2024-2053HIGH The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" us | Mar 21, 2024 | 7.5 | 55 | NO | YES |
CVE-2026-7574HIGH Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, including v1.1348.0, v1.1617.0, and v1.2278.0) validates only file presence and a v | Jun 24, 2026 | 8.7 | 38 | NO | NO |
CVE-2026-7415CRITICAL The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on the same network can subscribe to | May 7, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-7414CRITICAL Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all devices running this firmware and can | May 7, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-7413CRITICAL A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is | May 7, 2026 | 9.8 | 36 | NO | NO |
CVE-2025-35028CRITICAL By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI MCP server, the resultant comp | Nov 30, 2025 | 9.1 | 34 | NO | NO |
CVE-2024-2056CRITICAL Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service is running, running | Mar 5, 2024 | 9.8 | 34 | NO | NO |
CVE-2026-4946HIGH Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary command execution when an analyst i | Mar 29, 2026 | 8.8 | 32 | NO | NO |
CVE-2025-35027HIGH Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string | Sep 26, 2025 | 7.3 | 29 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA38 CVEs
21%
55%
24%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local17 (44.7%)
Network18 (47.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (7.9%)
Attack Complexity
Low36 (94.7%)
High2 (5.3%)
Unknown0 (0.0%)
User Interaction
None30 (78.9%)
Unknown0 (0.0%)
Required8 (21.1%)
Privileges Required
Low17 (44.7%)
High1 (2.6%)
None20 (52.6%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (38 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.6% of CVEs· 93rd percentile
Nuclei
1 CVE
2.6% of CVEs· 88th percentile
ExploitDB
1 CVE
2.6% of CVEs· 91st percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Austin Hackers Anonymous as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Austin Hackers Anonymous as a CNA — matched by CVE ID, not by organization name.