Vulnerability index

Browse CVEs

37 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nanomq HIGH 7.5
CVE-2026-36590

An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component

Mitigation only
Fix from $1,950 2026-07-15
Nanomq HIGH 7.5
CVE-2026-32135

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.11 have a remotely triggerable heap buffer overflow in t…

Fix: 0.24.11+
Fix from $1,950 2026-04-20
Nanomq HIGH 8.2
CVE-2026-34608

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.10, in NanoMQ's webhook_inproc.c, the hook_work_cb() func…

Fix: 0.24.10+
Fix from $1,950 2026-04-02
Cocoamqtt MEDIUM 6.5
CVE-2026-30867

CocoaMQTT is a MQTT 5.0 client library for iOS and macOS written in Swift. Prior to version 2.2.2, a vulnerability exists in the packet parsing logic…

Fix: 2.2.2+
Fix from $1,600 2026-04-02
Nanomq HIGH 7.5
CVE-2026-32696

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In NanoMQ version 0.24.6, after enabling auth.http_auth (HTTP authentication), …

Fix: 0.24.7+
Fix from $1,950 2026-03-30
Nanomq HIGH 7.5
CVE-2026-25627

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.8, NanoMQ’s MQTT-over-WebSocket transport can be crashed …

Fix: 0.24.8+
Fix from $1,950 2026-03-30
Nanomq HIGH 7.5
CVE-2026-21888

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. MQTT v5 Variable Byte Integer parsing out-of-bounds: get_var_integer() accepts …

Fix: after 0.24.6
Fix from $1,950 2026-03-11
Nanomq MEDIUM 5.3
CVE-2026-22040

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, by generating a combined traffic pattern of high-frequency p…

Fix: 0.24.6+
Fix from $1,600 2026-03-04
Nanomq MEDIUM 6.5
CVE-2025-68699

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, NanoMQ has a protocol parsing / forwarding inconsistency whe…

Patch available
Fix from $1,600 2026-02-04
Nanomq HIGH 7.5
CVE-2024-48077

NanoMQ v0.22.7 is vulnerable to Denial of Service (DoS) due to improper resource throttling. A crafted sequence of requests causes the recv-q queue t…

Mitigation only
Fix from $1,950 2026-01-15
Nanomq HIGH 7.5
CVE-2025-59946

NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing issue about sub info list which …

Fix: 0.24.4+
Fix from $1,950 2025-12-27
Nanomq CRITICAL 9.0
CVE-2025-59947

NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both shar…

Fix: 0.24.4+
Fix from $2,300 2025-12-15
Nanomq HIGH 8.8
CVE-2024-42655

An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wil…

Patch available
Fix from $1,950 2025-07-29
Nanomq HIGH 7.5
CVE-2024-42651

NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attackers to…

No fix yet
Fix from $1,950 2025-07-29
Nanomq HIGH 7.5
CVE-2024-42650

NanoMQ 0.17.5 was discovered to contain a segmentation fault via the component /nanomq/pub_handler.c. This vulnerability allows attackers to cause a …

Patch available
Fix from $1,950 2025-07-15
Nanomq MEDIUM 6.5
CVE-2024-42649

NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.

No fix yet
Fix from $1,600 2025-07-14
Nanomq HIGH 7.5
CVE-2024-42646

A segmentation fault in NanoMQ v0.21.10 allows attackers to cause a Denial of Service (DoS) via crafted messages.

No fix yet
Fix from $1,950 2025-07-14
Nanomq MEDIUM 6.5
CVE-2024-42648

NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via a crafted CONNECT message.

No fix yet
Fix from $1,600 2025-07-14
Neuron CRITICAL 9.8
CVE-2024-10964

A vulnerability classified as critical has been found in emqx neuron up to 2.10.0. Affected is the function handle_add_plugin in the library cmd.libr…

Fix: after 2.10.0
Fix from $2,300 2024-11-07
Neuron MEDIUM 6.5
CVE-2024-10965

A vulnerability classified as problematic was found in emqx neuron up to 2.10.0. Affected by this vulnerability is an unknown functionality of the fi…

Fix: after 2.10.0
Fix from $1,600 2024-11-07
Nanomq HIGH 7.5
CVE-2024-44460

An invalid read size in Nanomq v0.21.9 allows attackers to cause a Denial of Service (DoS).

No fix yet
Fix from $1,950 2024-09-12
Nanomq MEDIUM 6.8
CVE-2024-31036

A heap-buffer-overflow vulnerability in the read_byte function in NanoMQ v.0.21.7 allows attackers to cause a denial of service via transmission of c…

No fix yet
Fix from $1,600 2024-04-22
Nanomq HIGH 7.5
CVE-2024-31041

Null Pointer Dereference vulnerability in topic_filtern function in mqtt_parser.c in NanoMQ 0.21.7 allows attackers to cause a denial of service.

No fix yet
Fix from $1,950 2024-04-17
Nanomq MEDIUM 6.5
CVE-2024-25767

nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c.

No fix yet
Fix from $1,600 2024-02-26
Emqx MEDIUM 6.5
CVE-2023-37781

An issue in the emqx_sn plugin of EMQX v4.3.8 allows attackers to execute a directory traversal via uploading a crafted .txt file.

No fix yet
Fix from $1,600 2023-07-17
Nanomq HIGH 7.8
CVE-2023-34488

NanoMQ 0.17.5 has a one-byte heap-based buffer over-read in the conn_handler function of mqtt_parser.c when it processes malformed messages.

Patch available
Fix from $1,950 2023-06-12
Nanomq HIGH 7.5
CVE-2023-34494

NanoMQ 0.16.5 is vulnerable to heap-use-after-free in the nano_ctx_send function of nmq_mqtt.c.

Patch available
Fix from $1,950 2023-06-12
Nanomq HIGH 7.5
CVE-2023-33657

A use-after-free vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_mqtt_msg_get_publish_property(…

Patch available
Fix from $1,950 2023-06-08
Nanomq HIGH 7.5
CVE-2023-33658

A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_msg_get_pub_pid() in the…

Patch available
Fix from $1,950 2023-06-08
Nanomq HIGH 7.5
CVE-2023-33660

A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function copyn_str() in the file mqtt…

Patch available
Fix from $1,950 2023-06-08