7.3
CVE-2025-11792 -
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 41124.
7.8
CVE-2026-28727 -
Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber Protect 17 (macOS) before build 41186, Acronis Cyber Protect Cloud Agent (macOS) before build 41124.
6.9
CVE-2026-27770 - ePower epower.ie Insufficiently Protected Credentials
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
6.9
CVE-2026-24912 - ePower epower.ie Insufficient Session Expiration
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connectβ¦
8.7
CVE-2026-27778 - ePower epower.ie Improper Restriction of Excessive Authentication Attempts
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain unβ¦
5.3
CVE-2026-2589 - Greenshift β animation and page builder blocks <= 12.8.3 - Unauthenticated Sensitive Information Exβ¦
The Greenshift β animation and page builder blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 12.8.3 via the automated Settings Backup stored in a publicly accessible file. This makes it possible for unauthenticated attackers to extracβ¦
9.3
CVE-2026-22552 - ePower epower.ie Missing Authentication for Critical Function
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then iβ¦
6.5
CVE-2026-26122 - Microsoft ACI Confidential Containers Information Disclosure Vulnerability
Microsoft ACI Confidential Containers Information Disclosure Vulnerability
8.6
CVE-2026-26125 - Payment Orchestrator Service Elevation of Privilege Vulnerability
Payment Orchestrator Service Elevation of Privilege Vulnerability
6.7
CVE-2026-26124 - Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability
Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability