Bugcrowd Inc.

First CVE: Jul 30, 2025Active for: 1 year
9
CVEs Published
More CVEs Published than 25% of tracked CNAs
4.5
Avg CVEs / Year
More Avg CVEs / Year than 30% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by Bugcrowd Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 30, 2025
11 months ago
Most Recent CVE
Jun 5, 2026
49 days ago

Top CVEs

All CVEs published by Bugcrowd Inc. as a CNA, regardless of affected vendor or product.

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacke
Jun 5, 20269.840NONO
A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attac
Jun 5, 20269.840NONO
A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP fi
May 22, 20269.338NONO
A broken access control issue has been identified in the Talend Administration Center, that allows a user with “View” permission to modify the Talend Studio update URL. This issue
May 20, 20268.234NONO
A critical vulnerability in the Talend JobServer and Talend Runtime allows unauthenticated remote code execution via the JMX monitoring port. The attack vector is the JMX monitorin
Apr 14, 20269.834NONO
An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.12 allows an unauthenticated attacker withi
Jun 4, 20266.828NONO
A stored cross-site scripting vulnerability has been found in the Talend Administration Center. An attacker with permission to manage servers can store a XSS payload that can be tr
May 20, 20265.426NONO
the BMA login interface allows arbitrary JavaScript or HTML to be written straight into the page’s Document Object Model via the error= URL parameter
Jul 30, 20256.122NONO
The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A local threat actor with unprivileged access could execute arbit
Nov 18, 20253.216NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA9 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local3 (33.3%)
Network6 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None6 (66.7%)
Unknown0 (0.0%)
Required3 (33.3%)
Privileges Required
Low3 (33.3%)
High0 (0.0%)
None6 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Bugcrowd Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Bugcrowd Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs