emqx
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 41 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 8, 2021 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →EMQX: Stale plugins allow grants amplify a compromised admin/API key to remote code execution
EMQX QoS 2 PUBLISH Packet emqx_persistent_session_ds.erl race condition
NanoMQ has Heap Buffer Overflow in URI Parameter Parsing
nanomq: Heap-Buffer-Overflow in webhook_inproc.c via cJSON_Parse OOB Read
CocoaMQTT: Denial of Service via Reachable Assertion in `PUBLISH` Packet Parsing
NanoMQ HTTP Auth: Missing username/password can trigger a NULL-pointer strlen() in auth_http.c:set_data(), causing a process crash — SIGSEGV, remotely triggerable
nanomq: OOB Read / Crash (DoS) via Malformed MQTT Remaining Length over WebSocket
MQTT v5 Variable Byte Integer parsing out-of-bounds: get_var_integer()
NanoMQ 0.24.6 Use-After-Free Leading to Heap Corruption and Broker Crash
Monitor emqx in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.