Bugcrowd Inc.
First CVE: Jul 30, 2025Active for: 1 year
9
CVEs Published
More CVEs Published than 25% of tracked CNAs
4.5
Avg CVEs / Year
More Avg CVEs / Year than 30% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Bugcrowd Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 30, 2025
11 months ago
Most Recent CVE
Jun 5, 2026
49 days ago
Top CVEs
All CVEs published by Bugcrowd Inc. as a CNA, regardless of affected vendor or product.
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-7763CRITICAL A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacke | Jun 5, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-7762CRITICAL A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attac | Jun 5, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-9264CRITICAL A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP fi | May 22, 2026 | 9.3 | 38 | NO | NO |
CVE-2026-9057HIGH A broken access control issue has been identified in the Talend Administration Center, that allows a user with “View” permission to modify the Talend Studio update URL. This issue | May 20, 2026 | 8.2 | 34 | NO | NO |
CVE-2026-6264CRITICAL A critical vulnerability in the Talend JobServer and Talend Runtime allows unauthenticated remote code execution via the JMX monitoring port. The attack vector is the JMX monitorin | Apr 14, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-7764MEDIUM An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.12 allows an unauthenticated attacker withi | Jun 4, 2026 | 6.8 | 28 | NO | NO |
CVE-2026-9056MEDIUM A stored cross-site scripting vulnerability has been found in the Talend Administration Center. An attacker with permission to manage servers can store a XSS payload that can be tr | May 20, 2026 | 5.4 | 26 | NO | NO |
CVE-2025-8319MEDIUM the BMA login interface allows arbitrary JavaScript or HTML to be written straight into the page’s Document Object Model via the error= URL parameter | Jul 30, 2025 | 6.1 | 22 | NO | NO |
The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A local threat actor with unprivileged access could execute arbit | Nov 18, 2025 | 3.2 | 16 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA9 CVEs
11%
33%
11%
44%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (33.3%)
Network6 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None6 (66.7%)
Unknown0 (0.0%)
Required3 (33.3%)
Privileges Required
Low3 (33.3%)
High0 (0.0%)
None6 (66.7%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Bugcrowd Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Bugcrowd Inc. as a CNA — matched by CVE ID, not by organization name.