Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

63moons

First CVE: Nov 4, 2024Active for: 2 yearsTotal CVEs: 6

63moons operates a narrowly scoped product line centered on financial and trading platforms such as AERO and Wave 2.0, which serve institutional clients in capital markets. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, while its disclosures cluster around access and resource-control weaknesses—including authorization bypass, resource exhaustion, and excessive authentication handling—that reflect the authentication and rate-limiting demands of financial transaction systems. Defenders should monitor this vendor's advisories closely given the high-value nature of the systems it supports; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by 63moons over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 4, 2024
20 months ago
Most Recent CVE
Nov 4, 2024
627 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-51558CRITICAL
This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vuln
Nov 4, 20249.827NONO
CVE-2024-51561HIGH
This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerabi
Nov 4, 20247.522NONO
CVE-2024-51557MEDIUM
This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by send
Nov 4, 20246.520NONO
CVE-2024-51559MEDIUM
This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipu
Nov 4, 20246.519NONO
CVE-2024-51556MEDIUM
This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response. An authenticated remote attacker could exploit this vulnera
Nov 4, 20246.519NONO
CVE-2024-51560MEDIUM
This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint. An authenticated remote attacker could exploit this vulnera
Nov 4, 20244.315NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
67%
17%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (66.7%)
High0 (0.0%)
None2 (33.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by 63moons.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by 63moons — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For 63moons's Products

View all 1 CNAs →

Top CWEs