Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-20797 A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to cause stack corrup… Xweb 300d Pro Firmware after 1.12.1 Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-27647 The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same sess… Mobility46.se Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-27028 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen… Mobility46.se Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-26305 The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allo… Mobility46.se Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-26290 The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same sess… Ev.energy Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-25085 A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in which an unexpected return value from the authentication routine is later … Xweb 500b Pro Firmware after 1.12.1 Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-24663 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code exec… Xweb 500b Pro Firmware after 1.12.1 Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-24445 The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allo… Ev.energy Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-21718 An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to bypass the authentication re… Xweb 300d Pro Firmware after 1.12.1 Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-3271 A vulnerability was found in Tenda F453 1.0.0.3. This impacts the function fromP2pListFilter of the file /goform/P2pListFilterof of the component htt… F453 Firmware Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-27772 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen… Ev.energy Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-27767 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen… Swtchenergy.com Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-25945 The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allo… Ev2go.io Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-25851 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen… Chargemap.com Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-25114 The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allo… Cloudcharge.se Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-25113 The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allo… Swtchenergy.com Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-24731 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen… Ev2go.io Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-20792 The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allo… Chargemap.com Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-20781 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen… Cloudcharge.se Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.1 CVE-2026-28215 hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructur… Hoppscotch 2026.2.0+ Fix from $2,3002026-02-26 CRITICAL 9.8 CVE-2026-28213 EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password" functionality. When specifyi… Evershop 2.1.1+ Fix from $2,3002026-02-26 CRITICAL 9.8 CVE-2026-3261 A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settings/index.php of the component… School Management System Mitigation only Fix from $2,3002026-02-26 CRITICAL 9.8 CVE-2026-22207 OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows unauthenticated attackers to g… Patch available Fix from $2,3002026-02-26 CRITICAL 9.8 CVE-2025-50857 ZenTaoPMS v18.11 through v21.6.beta is vulnerable to Directory Traversal in /module/ai/control.php. This allows attackers to execute arbitrary code v… Mitigation only Fix from $2,3002026-02-26 CRITICAL 9.8 CVE-2026-27975 Ajenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access to a server to execute arbit… Ajenti 2.2.13+ Fix from $2,3002026-02-26 CRITICAL 9.8 CVE-2026-27966EPSS 34% Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allo… Langflow 1.8.0+ Fix from $2,3002026-02-26 CRITICAL 9.9 CVE-2026-27965 Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the bac… Vitess 22.0.4 / 23.0.3+ Fix from $2,3002026-02-26 CRITICAL 9.9 CVE-2026-27952 Agenta is an open-source LLMOps platform. In Agenta-API prior to version 0.48.1, a Python sandbox escape vulnerability existed in Agenta's custom cod… Agenta 0.48.1+ Fix from $2,3002026-02-26 CRITICAL 9.9 CVE-2026-27941 OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use t… Openlit Software Development Kit 1.37.1+ Fix from $2,3002026-02-26 CRITICAL 9.8 CVE-2026-27837 Dottie provides nested object access and manipulation in JavaScript. Versions 2.0.4 through 2.0.6 contain an incomplete fix for CVE-2023-26132. The p… Dottie 2.0.7+ Fix from $2,3002026-02-26