CyberDanube

First CVE: May 8, 2023Active for: 3 years
51
CVEs Published
More CVEs Published than 58% of tracked CNAs
12.8
Avg CVEs / Year
More Avg CVEs / Year than 60% of tracked CNAs
8.3
Avg CVSS Score
Higher Avg CVSS Score than 92% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by CyberDanube over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 8, 2023
3 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Top CVEs

All CVEs published by CyberDanube as a CNA, regardless of affected vendor or product.

51 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement data.This issue
Sep 25, 20249.876NOYES
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply cra
Jul 21, 202610.044NONO
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can s
Jul 21, 20269.541NONO
Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker c
Jul 21, 20269.440NONO
Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint
Jul 21, 202610.040NONO
Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can
Jul 21, 202610.040NONO
Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-sp
Jul 21, 202610.037NONO
Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical acc
Jul 21, 20268.636NONO
Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. An attac
Jul 21, 20268.636NONO
Missing input validation and OS command integration of the input in the utnserver Pro, utnserver ProMAX, INU-100 web-interface allows authenticated command injection.This issue aff
Jun 4, 20248.736NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA51 CVEs
Severity distribution among all CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local1 (2.0%)
Network46 (90.2%)
Unknown0 (0.0%)
Physical4 (7.8%)
Adjacent Network0 (0.0%)
Attack Complexity
Low50 (98.0%)
High1 (2.0%)
Unknown0 (0.0%)
User Interaction
None42 (82.4%)
Unknown0 (0.0%)
Required5 (9.8%)
Privileges Required
Low17 (33.3%)
High4 (7.8%)
None30 (58.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (51 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
5 CVEs
9.8% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by CyberDanube as a CNA.

Media Mentions

Media articles that mention a CVE ID published by CyberDanube as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs