9.4

CVSS3.1

CVE-2025-54816 - EVMAPA Missing Authentication for Critical Function

This vulnerability occurs when a WebSocket endpoint does not enforce proper authentication mechanisms, allowing unauthorized users to establish connections. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that…

πŸ“… Published: Jan. 22, 2026, 10:40 p.m. πŸ”„ Last Modified: Feb. 2, 2026, 7:56 p.m.

7.5

CVSS3.1

CVE-2025-53968 - EVMAPA Improper Restriction of Excessive Authentication Attempts

This vulnerability arises because there are no limitations on the number of authentication attempts a user can make. An attacker can exploit this weakness by continuously sending authentication requests, leading to a denial-of-service (DoS) condition. This can overwhelm the authentication syste…

πŸ“… Published: Jan. 22, 2026, 10:37 p.m. πŸ”„ Last Modified: Feb. 2, 2026, 7:59 p.m.

7.3

CVSS3.1

CVE-2025-55705 - EVMAPA Insufficient Session Expiration

This vulnerability occurs when the system permits multiple simultaneous connections to the backend using the same charging station ID. This can result in unauthorized access, data inconsistency, or potential manipulation of charging sessions. The lack of proper session management and expiration…

πŸ“… Published: Jan. 22, 2026, 10:32 p.m. πŸ”„ Last Modified: Feb. 12, 2026, 6:02 p.m.

6.1

CVSS3.1

CVE-2025-25051 - AutomationDirect CLICK Programmable Logic Controller Plaintext Storage of a Password

An attacker could decrypt sensitive data, impersonate legitimate users or devices, and potentially gain access to network resources for lateral attacks.

πŸ“… Published: Jan. 22, 2026, 10:21 p.m. πŸ”„ Last Modified: Jan. 26, 2026, 3:04 p.m.

8.9

CVSS4.0

CVE-2026-24124 - Dragonfly Manager Job API Allows Unauthenticated Access

Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/v1/jobs) lack JWT authentication middleware and RBAC authorization checks in the routing configuration. This allows any unauthenticated user with acce…

πŸ“… Published: Jan. 22, 2026, 10:20 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 9:42 p.m.

6.1

CVSS3.1

CVE-2025-67652 - AutomationDirect CLICK Programmable Logic Controller Weak Encoding for Password

An attacker with access to the project file could use the exposed credentials to impersonate users, escalate privileges, or gain unauthorized access to systems and services. The absence of robust encryption or secure handling mechanisms increases the likelihood of this type of exploitation, lea…

πŸ“… Published: Jan. 22, 2026, 10:17 p.m. πŸ”„ Last Modified: Jan. 26, 2026, 3:04 p.m.

5.3

CVSS3.1

CVE-2026-24117 - Rekor affected by Server-Side Request Forgery (SSRF) via provided public key URL

Rekor is a software supply chain transparency log. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary internal services because /api/v1/index/retrieve supports retrieving a public key via user-provided URL. Since the SSRF only can trigger GET requests, the request cannot mutate st…

πŸ“… Published: Jan. 22, 2026, 10:05 p.m. πŸ”„ Last Modified: Feb. 2, 2026, 3:07 p.m.

9.1

CVSS3.1

CVE-2026-20912 - Gitea: Cross-Repository Authorization Bypass via Release Attachment Linking Leads to Private Attach…

Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users.

πŸ“… Published: Jan. 22, 2026, 10:01 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 10:03 p.m.

4.3

CVSS3.1

CVE-2026-20888 - Gitea Pull Requests Auto-Merge: Read-Only Users Can Cancel Scheduled Auto-Merge via Web Endpoint (A…

Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users.

πŸ“… Published: Jan. 22, 2026, 10:01 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 10 p.m.

9.1

CVSS3.1

CVE-2026-20897 - Gitea Git LFS Lock Deletion Broken Access Control (Cross-Repo IDOR)

Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories.

πŸ“… Published: Jan. 22, 2026, 10:01 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 10:02 p.m.
Total resulsts: 343923
Page 1467 of 34,393
Β« previous page Β» next page
Filters