8.7

CVSS4.0

CVE-2026-27778 - ePower epower.ie Improper Restriction of Excessive Authentication Attempts

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain un…

πŸ“… Published: March 5, 2026, 11:36 p.m. πŸ”„ Last Modified: May 6, 2026, 2:42 p.m.

5.3

CVSS3.1

CVE-2026-2589 - Greenshift – animation and page builder blocks <= 12.8.3 - Unauthenticated Sensitive Information Ex…

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 12.8.3 via the automated Settings Backup stored in a publicly accessible file. This makes it possible for unauthenticated attackers to extrac…

πŸ“… Published: March 5, 2026, 11:21 p.m. πŸ”„ Last Modified: April 22, 2026, 9:27 p.m.

9.3

CVSS4.0

CVE-2026-22552 - ePower epower.ie Missing Authentication for Critical Function

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then i…

πŸ“… Published: March 5, 2026, 11:18 p.m. πŸ”„ Last Modified: May 6, 2026, 2:44 p.m.

6.5

CVSS3.1

CVE-2026-26122 - Microsoft ACI Confidential Containers Information Disclosure Vulnerability

Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose information over a network.

πŸ“… Published: March 5, 2026, 10:18 p.m. πŸ”„ Last Modified: April 15, 2026, 5 p.m.

8.6

CVSS3.1

CVE-2026-26125 - Payment Orchestrator Service Elevation of Privilege Vulnerability

Payment Orchestrator Service Elevation of Privilege Vulnerability

πŸ“… Published: March 5, 2026, 10:18 p.m. πŸ”„ Last Modified: April 15, 2026, 5 p.m.

6.7

CVSS3.1

CVE-2026-26124 - Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability

'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.

πŸ“… Published: March 5, 2026, 10:18 p.m. πŸ”„ Last Modified: April 15, 2026, 5 p.m.

9.8

CVSS3.1

CVE-2026-21536 - Microsoft Devices Pricing Program Remote Code Execution Vulnerability

Microsoft Devices Pricing Program Remote Code Execution Vulnerability

πŸ“… Published: March 5, 2026, 10:18 p.m. πŸ”„ Last Modified: April 17, 2026, 12:45 p.m.

6.7

CVSS3.1

CVE-2026-23651 - Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability

Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.

πŸ“… Published: March 5, 2026, 10:18 p.m. πŸ”„ Last Modified: April 15, 2026, 5 p.m.

4.8

CVSS4.0

CVE-2026-3606 - Ettercap etterfilter ef_output.c add_data_segment out-of-bounds

A vulnerability has been found in Ettercap 0.8.4-Garofalo. Affected by this vulnerability is the function add_data_segment of the file src/ettercap/utils/etterfilter/ef_output.c of the component etterfilter. The manipulation leads to out-of-bounds read. Local access is required to approach this att…

πŸ“… Published: March 5, 2026, 10:02 p.m. πŸ”„ Last Modified: April 16, 2026, noon

8.2

CVSS4.0

CVE-2026-29613 - OpenClaw < 2026.2.12 - Webhook Authentication Bypass via Loopback remoteAddress Trust

OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in which it authenticates requests based solely on loopback remoteAddress without validating forwarding headers, allowing bypass of configured webhook passwords. When the gateway operat…

πŸ“… Published: March 5, 2026, 10 p.m. πŸ”„ Last Modified: April 16, 2026, noon
Total resulsts: 349182
Page 1290 of 34,919
Β« previous page Β» next page
Filters