63moons operates a narrowly scoped product line centered on financial and trading platforms such as AERO and Wave 2.0, which serve institutional clients in capital markets. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, while its disclosures cluster around access and resource-control weaknesses—including authorization bypass, resource exhaustion, and excessive authentication handling—that reflect the authentication and rate-limiting demands of financial transaction systems. Defenders should monitor this vendor's advisories closely given the high-value nature of the systems it supports; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 63moons over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-51558CRITICAL This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vuln | Nov 4, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-51561HIGH This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerabi | Nov 4, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-51557MEDIUM This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by send | Nov 4, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-51559MEDIUM This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipu | Nov 4, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-51556MEDIUM This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response. An authenticated remote attacker could exploit this vulnera | Nov 4, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-51560MEDIUM This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint. An authenticated remote attacker could exploit this vulnera | Nov 4, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 63moons.
Media articles that mention a CVE ID that affects a product developed by 63moons — matched by CVE ID, not by vendor name.