Vulnerabilities > 63Moons

DATE CVE VULNERABILITY TITLE RISK
2024-11-04 CVE-2024-51556 Use of a Broken or Risky Cryptographic Algorithm vulnerability in 63Moons Aero and Wave 2.0
This vulnerability exists in the Wave 2.0 due to weak encryption of sensitive data received at the API response.
network
low complexity
63moons CWE-327
6.5
2024-11-04 CVE-2024-51557 Allocation of Resources Without Limits or Throttling vulnerability in 63Moons Aero and Wave 2.0
This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint.
network
low complexity
63moons CWE-770
6.5
2024-11-04 CVE-2024-51558 Improper Restriction of Excessive Authentication Attempts vulnerability in 63Moons Aero and Wave 2.0
This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed authentication attempts on its API based login.
network
low complexity
63moons CWE-307
critical
9.8
2024-11-04 CVE-2024-51559 Authorization Bypass Through User-Controlled Key vulnerability in 63Moons Aero and Wave 2.0
This vulnerability exists in the Wave 2.0 due to missing authorization check on certain API endpoints.
network
low complexity
63moons CWE-639
6.5
2024-11-04 CVE-2024-51560 Information Exposure Through an Error Message vulnerability in 63Moons Aero and Wave 2.0
This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint.
network
low complexity
63moons CWE-209
4.3
2024-11-04 CVE-2024-51561 Unspecified vulnerability in 63Moons Aero and Wave 2.0
This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints.
network
low complexity
63moons
7.5