ONEKEY GmbH

First CVE: Dec 1, 2022Active for: 4 years
20
CVEs Published
More CVEs Published than 39% of tracked CNAs
5.0
Avg CVEs / Year
More Avg CVEs / Year than 32% of tracked CNAs
8.4
Avg CVSS Score
Higher Avg CVSS Score than 92% of tracked CNAs
5.0%
In CISA KEV
Higher KEV Rate than 96% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by ONEKEY GmbH as a CNA, 0.0% affect products that ONEKEY GmbH develops as a vendor.

100.0%
Self-reported: 0Third-party: 20

Of all the CVEs published that affect products developed by ONEKEY GmbH, 0.0% are self-published by ONEKEY GmbH as a CNA.

100.0%
Self-published: 0Published by other CNAs: 1

Trends Over Time

The number and severity of CVEs published by ONEKEY GmbH over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 1, 2022
3 years ago
Most Recent CVE
Sep 12, 2025
315 days ago

Top CVEs

All CVEs published by ONEKEY GmbH as a CNA, regardless of affected vendor or product.

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written i
May 21, 20258.897YESYES
The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on port 80. This web management inte
May 28, 20259.381NOYES
A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. By crafting a malicious PFS filesystem file, an attacker can get bi
Jan 26, 20237.847NOYES
NetModule NSRW web administration interface executes an OS command constructed with unsanitized user input. A successful exploit could allow an authenticated user to execute arbitr
Feb 16, 20238.835NONO
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauthenticated attacker to inject arbitrary OS c
Dec 1, 20229.834NONO
The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on port 80. This web management inte
Sep 12, 20259.333NONO
The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on port 80. This web management inte
Sep 12, 20259.333NONO
A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote attacker to execute arbitrary commands with elevated privileg
May 16, 20249.432NONO
The affected device expose a network service called "rftest" that is vulnerable to unauthenticated command injection on ports TCP/8888, TCP/8889, and TCP/8890. By successfully expl
May 27, 20248.830NONO
The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements multiple features that are affected by command injections and s
Apr 16, 20249.829NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA20 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local4 (20.0%)
Network9 (45.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (10.0%)
Attack Complexity
Low18 (90.0%)
High2 (10.0%)
Unknown0 (0.0%)
User Interaction
None16 (80.0%)
Unknown0 (0.0%)
Required4 (20.0%)
Privileges Required
Low4 (20.0%)
High1 (5.0%)
None15 (75.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (20 CVEs).

CISA KEV
1 CVE
5.0% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
10.0% of CVEs· 96th percentile
ExploitDB
1 CVE
5.0% of CVEs· 95th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by ONEKEY GmbH as a CNA.

Media Mentions

Media articles that mention a CVE ID published by ONEKEY GmbH as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs