Aa Team maintains a focused vulnerability footprint centered around the Wzone product, a narrowly scoped offering with a modest presence in the vendor landscape. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aa Team over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-33544CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through | Apr 29, 2024 | 9.3 | 29 | NO | NO |
CVE-2026-27040HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AA-Team WZone woozone allows Path Traversal.This issue affects WZone: from n/a throu | Mar 25, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-27039HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone woozone allows Blind SQL Injection.This issue affects WZone: fro | Mar 25, 2026 | 8.5 | 26 | NO | NO |
CVE-2024-33546CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through | Apr 29, 2024 | 9.6 | 26 | NO | NO |
CVE-2024-33547HIGH Missing Authorization vulnerability in AA-Team WZone.This issue affects WZone: from n/a through 14.0.10. | Jun 9, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-33545CRITICAL Missing Authorization vulnerability in AA-Team WZone.This issue affects WZone: from n/a through 14.0.10. | Jun 9, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-33549HIGH Improper Privilege Management vulnerability in AA-Team WZone allows Privilege Escalation.This issue affects WZone: from n/a through 14.0.10. | May 17, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-33548HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team WZone allows Reflected XSS.This issue affects WZone: from n/a through | Apr 29, 2024 | 7.1 | 20 | NO | NO |
CVE-2026-25473MEDIUM Missing Authorization vulnerability in AA-Team WZone woozone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WZone: from n/a through <= 1 | Feb 19, 2026 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aa Team.
Media articles that mention a CVE ID that affects a product developed by Aa Team — matched by CVE ID, not by vendor name.