Common Vulnerabilities and Exposures (CVE)

CVE-2026-25945

Mar 3, 2026 01:33:14 UTC

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimat...

CVE-2026-24445

Mar 3, 2026 01:32:18 UTC

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimat...

CVE-2026-26290

Mar 3, 2026 01:31:40 UTC

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables...

CVE-2026-25774

Mar 3, 2026 01:30:49 UTC

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

CVE-2026-27028

Mar 3, 2026 01:29:48 UTC

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint u...

CVE-2026-26305

Mar 3, 2026 01:29:07 UTC

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimat...

CVE-2026-27647

Mar 3, 2026 01:28:28 UTC

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables...

CVE-2026-20910

Mar 3, 2026 01:27:24 UTC

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field of the firmware upda...

CVE-2026-24689

Mar 3, 2026 01:26:47 UTC

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field of the firmware upd...

CVE-2026-25109

Mar 3, 2026 01:26:09 UTC

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field when accessing the...

CVE-2026-20902

Mar 3, 2026 01:25:09 UTC

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the map filename field during the m...

CVE-2026-1585

Mar 3, 2026 01:11:36 UTC

An unquoted Windows service executable path vulnerability in IJ Scan Utility for Windows versions 1.1.2 through 1.5.0 may allow a local attacker to execute a malicious file with the privileges of the affected service.

CVE-2026-25859

Mar 2, 2026 22:58:07 UTC

Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resulting in unauthorized migration operations.

CVE-2026-25568

Mar 2, 2026 22:58:05 UTC

WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPrivateOnly is not sufficiently enforced at board creation time. When allowPrivateOnly is enabled, users can still creat...

CVE-2026-25567

Mar 2, 2026 22:58:04 UTC

WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The endpoint accepts an authorId from the request body, allowing an authenticated user to spoof the recorded comment author by...