Maritime Hacking Village
First CVE: Jan 14, 2026Active for: 1 year
11
CVEs Published
More CVEs Published than 28% of tracked CNAs
11.0
Avg CVEs / Year
More Avg CVEs / Year than 55% of tracked CNAs
8.2
Avg CVSS Score
Higher Avg CVSS Score than 89% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Maritime Hacking Village over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 14, 2026
6 months ago
Most Recent CVE
Mar 6, 2026
140 days ago
Top CVEs
All CVEs published by Maritime Hacking Village as a CNA, regardless of affected vendor or product.
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22238CRITICAL The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX admin APIs. An unauthenticated remote attacker could exploit this vulnerability by sending speci | Jan 14, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-22236CRITICAL The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX backend APIs. An unauthenticated remote attacker could exploit this vulnerability by sending spe | Jan 14, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-2249CRITICAL METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote a | Feb 11, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-2248CRITICAL METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote a | Feb 11, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-22237CRITICAL The vulnerability exists in BLUVOYIX due to the exposure of sensitive internal API documentation. An unauthenticated remote attacker could exploit this vulnerability by sending spe | Jan 14, 2026 | 9.8 | 30 | NO | NO |
CVE-2026-22240HIGH The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unauthenticated APIs. An unauthenticated remote attacker could e | Jan 14, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-2754HIGH Navtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints. An unauthenticated remote attacker with network access to th | Mar 6, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-2753HIGH An Absolute Path Traversal vulnerability exists in Navtor NavBox. The application exposes an HTTP service that fails to properly sanitize user-supplied path input. Unauthenticated | Mar 6, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-2250HIGH The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and export the internal telemetry SQLite database containing sensit | Feb 11, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-22239MEDIUM The vulnerability exists in BLUVOYIX due to design flaws in the email sending API. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted | Jan 14, 2026 | 5.3 | 23 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA11 CVEs
18%
36%
45%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None11 (100.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Maritime Hacking Village as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Maritime Hacking Village as a CNA — matched by CVE ID, not by organization name.