Vulnerabilities in emqx
6 resultsVexday analysis
EMQX apresenta 4 vulnerabilidades conhecidas no Vexday, nenhuma sob exploração ativa no momento. Não há CVEs críticas registradas, e a ameaça não é recente—nenhuma publicação nos últimos 90 dias. A fraqueza predominante (CWE-119, improper restriction of operations within buffer bounds) sugere riscos de memória que merecem atenção em ambientes de produção, mas o perfil geral indica risco moderado e controlável.
CVE-2024-10964MEDIUMemqx neuron plugin_handle.c handle_add_plugin buffer overflowEPSS 0.7%CVE-2024-10965MEDIUMemqx neuron JSON File schema information disclosureEPSS 0.5%CVE-2025-62413MEDIUMMQTTX vulnerable to cross-site scripting via improper message payload renderingEPSS 0.3%CVE-2026-30867MEDIUMCocoaMQTT: Denial of Service via Reachable Assertion in `PUBLISH` Packet ParsingEPSS 0.3%CVE-2025-52136LOWIn EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web interface. NOTE: the Supplier's position is tEPSS 0.3%CVE-2026-44725MEDIUMEMQX: Stale plugins allow grants amplify a compromised admin/API key to remote code executionEPSS 0.3%