CyberDanube
First CVE: May 8, 2023Active for: 3 years
51
CVEs Published
More CVEs Published than 58% of tracked CNAs
12.8
Avg CVEs / Year
More Avg CVEs / Year than 60% of tracked CNAs
8.3
Avg CVSS Score
Higher Avg CVSS Score than 92% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by CyberDanube over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 8, 2023
3 years ago
Most Recent CVE
Jul 21, 2026
3 days ago
Top CVEs
All CVEs published by CyberDanube as a CNA, regardless of affected vendor or product.
51 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8877CRITICAL Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement data.This issue | Sep 25, 2024 | 9.8 | 76 | NO | YES |
CVE-2026-8985CRITICAL Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply cra | Jul 21, 2026 | 10.0 | 44 | NO | NO |
CVE-2026-8986CRITICAL Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can s | Jul 21, 2026 | 9.5 | 41 | NO | NO |
CVE-2026-8987CRITICAL Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker c | Jul 21, 2026 | 9.4 | 40 | NO | NO |
CVE-2026-8984CRITICAL Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint | Jul 21, 2026 | 10.0 | 40 | NO | NO |
CVE-2026-8983CRITICAL Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can | Jul 21, 2026 | 10.0 | 40 | NO | NO |
CVE-2026-8982CRITICAL Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-sp | Jul 21, 2026 | 10.0 | 37 | NO | NO |
CVE-2026-8989HIGH Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical acc | Jul 21, 2026 | 8.6 | 36 | NO | NO |
CVE-2026-8988HIGH Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. An attac | Jul 21, 2026 | 8.6 | 36 | NO | NO |
CVE-2024-5421HIGH Missing input validation and OS command integration of the input in the utnserver Pro, utnserver ProMAX, INU-100 web-interface allows authenticated command injection.This issue aff | Jun 4, 2024 | 8.7 | 36 | NO | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA51 CVEs
16%
43%
41%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (2.0%)
Network46 (90.2%)
Unknown0 (0.0%)
Physical4 (7.8%)
Adjacent Network0 (0.0%)
Attack Complexity
Low50 (98.0%)
High1 (2.0%)
Unknown0 (0.0%)
User Interaction
None42 (82.4%)
Unknown0 (0.0%)
Required5 (9.8%)
Privileges Required
Low17 (33.3%)
High4 (7.8%)
None30 (58.8%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (51 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
5 CVEs
9.8% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by CyberDanube as a CNA.
Media Mentions
Media articles that mention a CVE ID published by CyberDanube as a CNA — matched by CVE ID, not by organization name.