VulnSea

themoos has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 7.5 (high), with 2 rated critical. None have a confirmed exploitation report. Most affected products: core-moos (4), essential-moos (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
5 prev 0

Products

  • core-moos 4
  • essential-moos 1
5
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

themoos vulnerabilities

CVEs affecting themoos, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-85453Medium· 6.1
2w ago

MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts

MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts. Any MOOS publisher can set variable values containing script payloads that execute in the b…

Sunlitthemoos · core-moosEPSS 0.19%via NVD
CVE-2026-85443High· 7.5
2w ago

MOOS core-moos through 10.4.0 contains a denial of service vulnerability in MOOSCommServer::ListenLoop() where the accept thread performs a blocking receive without timeout during the wire-protocol handshake

MOOS core-moos through 10.4.0 contains a denial of service vulnerability in MOOSCommServer::ListenLoop() where the accept thread performs a blocking receive without timeout during the wire-protocol handshake. An attacker can open a TCP c…

Twilightthemoos · core-moosEPSS 0.35%via NVD
CVE-2026-85433Critical· 9.8
2w ago

MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime

MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send crafted PSHARE_CMD messages with cmd=output or c…

Midnightthemoos · essential-moosEPSS 0.34%via NVD
CVE-2026-85428Critical· 9.8
2w ago

MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables

MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP requests with variable names and values to t…

Midnightthemoos · core-moosEPSS 0.55%via NVD
CVE-2026-85454Medium· 6.1
2w ago

MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stack buffer

MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stack buffer. Attackers controlling the serial line can send a full-l…

Sunlitthemoos · core-moosEPSS 0.22%via NVD
themoos vulnerabilities (CVEs) · VulnSea