Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xweb 300d Pro Firmware CRITICAL 9.8
CVE-2026-20797

A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to cause stack corrup…

Fix: after 1.12.1
Fix from $2,300 2026-02-27
Mobility46.se CRITICAL 9.8
CVE-2026-27647

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same sess…

Mitigation only
Fix from $2,300 2026-02-27
Mobility46.se CRITICAL 9.8
CVE-2026-27028

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen…

Mitigation only
Fix from $2,300 2026-02-27
Mobility46.se CRITICAL 9.8
CVE-2026-26305

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allo…

Mitigation only
Fix from $2,300 2026-02-27
Ev.energy CRITICAL 9.8
CVE-2026-26290

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same sess…

Mitigation only
Fix from $2,300 2026-02-27
Xweb 500b Pro Firmware CRITICAL 9.8
CVE-2026-25085

A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in which an unexpected return value from the authentication routine is later …

Fix: after 1.12.1
Fix from $2,300 2026-02-27
Xweb 500b Pro Firmware CRITICAL 9.8
CVE-2026-24663

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code exec…

Fix: after 1.12.1
Fix from $2,300 2026-02-27
Ev.energy CRITICAL 9.8
CVE-2026-24445

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allo…

Mitigation only
Fix from $2,300 2026-02-27
Xweb 300d Pro Firmware CRITICAL 9.8
CVE-2026-21718

An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to bypass the authentication re…

Fix: after 1.12.1
Fix from $2,300 2026-02-27
F453 Firmware CRITICAL 9.8
CVE-2026-3271

A vulnerability was found in Tenda F453 1.0.0.3. This impacts the function fromP2pListFilter of the file /goform/P2pListFilterof of the component htt…

Mitigation only
Fix from $2,300 2026-02-27
Ev.energy CRITICAL 9.8
CVE-2026-27772

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen…

Mitigation only
Fix from $2,300 2026-02-27
Swtchenergy.com CRITICAL 9.8
CVE-2026-27767

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen…

Mitigation only
Fix from $2,300 2026-02-27
Ev2go.io CRITICAL 9.8
CVE-2026-25945

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allo…

Mitigation only
Fix from $2,300 2026-02-27
Chargemap.com CRITICAL 9.8
CVE-2026-25851

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen…

Mitigation only
Fix from $2,300 2026-02-27
Cloudcharge.se CRITICAL 9.8
CVE-2026-25114

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allo…

Mitigation only
Fix from $2,300 2026-02-27
Swtchenergy.com CRITICAL 9.8
CVE-2026-25113

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allo…

Mitigation only
Fix from $2,300 2026-02-27
Ev2go.io CRITICAL 9.8
CVE-2026-24731

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen…

Mitigation only
Fix from $2,300 2026-02-27
Chargemap.com CRITICAL 9.8
CVE-2026-20792

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allo…

Mitigation only
Fix from $2,300 2026-02-27
Cloudcharge.se CRITICAL 9.8
CVE-2026-20781

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen…

Mitigation only
Fix from $2,300 2026-02-27
Hoppscotch CRITICAL 9.1
CVE-2026-28215

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructur…

Fix: 2026.2.0+
Fix from $2,300 2026-02-26
Evershop CRITICAL 9.8
CVE-2026-28213

EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password" functionality. When specifyi…

Fix: 2.1.1+
Fix from $2,300 2026-02-26
School Management System CRITICAL 9.8
CVE-2026-3261

A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settings/index.php of the component…

Mitigation only
Fix from $2,300 2026-02-26
Unclassified CRITICAL 9.8
CVE-2026-22207

OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows unauthenticated attackers to g…

Patch available
Fix from $2,300 2026-02-26
Unclassified CRITICAL 9.8
CVE-2025-50857

ZenTaoPMS v18.11 through v21.6.beta is vulnerable to Directory Traversal in /module/ai/control.php. This allows attackers to execute arbitrary code v…

Mitigation only
Fix from $2,300 2026-02-26
Ajenti CRITICAL 9.8
CVE-2026-27975

Ajenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access to a server to execute arbit…

Fix: 2.2.13+
Fix from $2,300 2026-02-26
Langflow CRITICAL 9.8
CVE-2026-27966EPSS 34%

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allo…

Fix: 1.8.0+
Fix from $2,300 2026-02-26
Vitess CRITICAL 9.9
CVE-2026-27965

Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the bac…

Fix: 22.0.4 / 23.0.3+
Fix from $2,300 2026-02-26
Agenta CRITICAL 9.9
CVE-2026-27952

Agenta is an open-source LLMOps platform. In Agenta-API prior to version 0.48.1, a Python sandbox escape vulnerability existed in Agenta's custom cod…

Fix: 0.48.1+
Fix from $2,300 2026-02-26
Openlit Software Development Kit CRITICAL 9.9
CVE-2026-27941

OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use t…

Fix: 1.37.1+
Fix from $2,300 2026-02-26
Dottie CRITICAL 9.8
CVE-2026-27837

Dottie provides nested object access and manipulation in JavaScript. Versions 2.0.4 through 2.0.6 contain an incomplete fix for CVE-2023-26132. The p…

Fix: 2.0.7+
Fix from $2,300 2026-02-26