The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is du…
Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to …
Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administ…
Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker t…
A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP…
A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the pas…
The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks.
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function.
The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks.
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets function.
PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks its **unverified** `iss` claim against an issuer allowlist using Python's `urlp…
Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration whic…
Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a tempor…
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by op…
A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as roo…
The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the lo…
The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verificat…
An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware up…
An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause…
Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can …
The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UI…
A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting …
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injectio…
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in …
A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compro…
A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as r…
An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default crede…
A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands …
An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches fro…