Top technology
Linux 13139
Google 12696
Microsoft 12396
Oracle 7386
Apple 6696
Ibm 6475
Adobe 6406
Cisco 5764
Debian 3920
Apache 2913
Mozilla 2912
Redhat 2620
CRITICAL 9.8
CVE-2026-20797
A stack based buffer overflow exists in an API route of XWEB Pro version
1.12.1 and prior, enabling unauthenticated attackers to cause stack
corrup…
Xweb 300d Pro Firmware
after 1.12.1
CRITICAL 9.8
CVE-2026-27647
The WebSocket backend uses charging station identifiers to uniquely
associate sessions but allows multiple endpoints to connect using the
same sess…
Mobility46.se
Mitigation only
CRITICAL 9.8
CVE-2026-27028
WebSocket endpoints lack proper authentication mechanisms, enabling
attackers to perform unauthorized station impersonation and manipulate
data sen…
Mobility46.se
Mitigation only
CRITICAL 9.8
CVE-2026-26305
The WebSocket Application Programming Interface lacks restrictions on
the number of authentication requests. This absence of rate limiting may
allo…
Mobility46.se
Mitigation only
CRITICAL 9.8
CVE-2026-26290
The WebSocket backend uses charging station identifiers to uniquely
associate sessions but allows multiple endpoints to connect using the
same sess…
Ev.energy
Mitigation only
CRITICAL 9.8
CVE-2026-25085
A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in
which an unexpected return value from the authentication routine is
later …
Xweb 500b Pro Firmware
after 1.12.1
CRITICAL 9.8
CVE-2026-24663
An OS command injection vulnerability exists in XWEB Pro version 1.12.1
and prior, enabling an unauthenticated attacker to achieve remote code
exec…
Xweb 500b Pro Firmware
after 1.12.1
CRITICAL 9.8
CVE-2026-24445
The WebSocket Application Programming Interface lacks restrictions on
the number of authentication requests. This absence of rate limiting may
allo…
Ev.energy
Mitigation only
CRITICAL 9.8
CVE-2026-21718
An authentication bypass vulnerability exists in Copeland XWEB Pro
version 1.12.1 and prior, enabling any attackers to bypass the
authentication re…
Xweb 300d Pro Firmware
after 1.12.1
CRITICAL 9.8
CVE-2026-3271
A vulnerability was found in Tenda F453 1.0.0.3. This impacts the function fromP2pListFilter of the file /goform/P2pListFilterof of the component htt…
F453 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-27772
WebSocket endpoints lack proper authentication mechanisms, enabling
attackers to perform unauthorized station impersonation and manipulate
data sen…
Ev.energy
Mitigation only
CRITICAL 9.8
CVE-2026-27767
WebSocket endpoints lack proper authentication mechanisms, enabling
attackers to perform unauthorized station impersonation and manipulate
data sen…
Swtchenergy.com
Mitigation only
CRITICAL 9.8
CVE-2026-25945
The WebSocket Application Programming Interface lacks restrictions on
the number of authentication requests. This absence of rate limiting may
allo…
Ev2go.io
Mitigation only
CRITICAL 9.8
CVE-2026-25851
WebSocket endpoints lack proper authentication mechanisms, enabling
attackers to perform unauthorized station impersonation and manipulate
data sen…
Chargemap.com
Mitigation only
CRITICAL 9.8
CVE-2026-25114
The WebSocket Application Programming Interface lacks restrictions on
the number of authentication requests. This absence of rate limiting may
allo…
Cloudcharge.se
Mitigation only
CRITICAL 9.8
CVE-2026-25113
The WebSocket Application Programming Interface lacks restrictions on
the number of authentication requests. This absence of rate limiting may
allo…
Swtchenergy.com
Mitigation only
CRITICAL 9.8
CVE-2026-24731
WebSocket endpoints lack proper authentication mechanisms, enabling
attackers to perform unauthorized station impersonation and manipulate
data sen…
Ev2go.io
Mitigation only
CRITICAL 9.8
CVE-2026-20792
The WebSocket Application Programming Interface lacks restrictions on
the number of authentication requests. This absence of rate limiting may
allo…
Chargemap.com
Mitigation only
CRITICAL 9.8
CVE-2026-20781
WebSocket endpoints lack proper authentication mechanisms, enabling
attackers to perform unauthorized station impersonation and manipulate
data sen…
Cloudcharge.se
Mitigation only
CRITICAL 9.1
CVE-2026-28215
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructur…
Hoppscotch
2026.2.0+
CRITICAL 9.8
CVE-2026-28213
EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password" functionality. When specifyi…
Evershop
2.1.1+
CRITICAL 9.8
CVE-2026-3261
A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settings/index.php of the component…
School Management System
Mitigation only
CRITICAL 9.8
CVE-2026-22207
OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows unauthenticated attackers to g…
Patch available
CRITICAL 9.8
CVE-2025-50857
ZenTaoPMS v18.11 through v21.6.beta is vulnerable to Directory Traversal in /module/ai/control.php. This allows attackers to execute arbitrary code v…
Mitigation only
CRITICAL 9.8
CVE-2026-27975
Ajenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access to a server to execute arbit…
Ajenti
2.2.13+
CRITICAL 9.8
CVE-2026-27966EPSS 34%
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allo…
Langflow
1.8.0+
CRITICAL 9.9
CVE-2026-27965
Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the bac…
Vitess
22.0.4 / 23.0.3+
CRITICAL 9.9
CVE-2026-27952
Agenta is an open-source LLMOps platform. In Agenta-API prior to version 0.48.1, a Python sandbox escape vulnerability existed in Agenta's custom cod…
Agenta
0.48.1+
CRITICAL 9.9
CVE-2026-27941
OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use t…
Openlit Software Development Kit
1.37.1+
CRITICAL 9.8
CVE-2026-27837
Dottie provides nested object access and manipulation in JavaScript. Versions 2.0.4 through 2.0.6 contain an incomplete fix for CVE-2023-26132. The p…
Dottie
2.0.7+