8.7
CVE-2026-27778 - ePower epower.ie Improper Restriction of Excessive Authentication Attempts
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain unβ¦
5.3
CVE-2026-2589 - Greenshift β animation and page builder blocks <= 12.8.3 - Unauthenticated Sensitive Information Exβ¦
The Greenshift β animation and page builder blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 12.8.3 via the automated Settings Backup stored in a publicly accessible file. This makes it possible for unauthenticated attackers to extracβ¦
9.3
CVE-2026-22552 - ePower epower.ie Missing Authentication for Critical Function
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then iβ¦
6.5
CVE-2026-26122 - Microsoft ACI Confidential Containers Information Disclosure Vulnerability
Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
8.6
CVE-2026-26125 - Payment Orchestrator Service Elevation of Privilege Vulnerability
Payment Orchestrator Service Elevation of Privilege Vulnerability
6.7
CVE-2026-26124 - Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability
'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
9.8
CVE-2026-21536 - Microsoft Devices Pricing Program Remote Code Execution Vulnerability
Microsoft Devices Pricing Program Remote Code Execution Vulnerability
6.7
CVE-2026-23651 - Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability
Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
4.8
CVE-2026-3606 - Ettercap etterfilter ef_output.c add_data_segment out-of-bounds
A vulnerability has been found in Ettercap 0.8.4-Garofalo. Affected by this vulnerability is the function add_data_segment of the file src/ettercap/utils/etterfilter/ef_output.c of the component etterfilter. The manipulation leads to out-of-bounds read. Local access is required to approach this attβ¦
8.2
CVE-2026-29613 - OpenClaw < 2026.2.12 - Webhook Authentication Bypass via Loopback remoteAddress Trust
OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in which it authenticates requests based solely on loopback remoteAddress without validating forwarding headers, allowing bypass of configured webhook passwords. When the gateway operatβ¦