Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-20895 — EV2GO ev2go.io Insufficient Session Expiration

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in pre…

ev2go.io | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-20792 — Chargemap chargemap.com Improper Restriction of Excessive Authentication Attempts

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks…

chargemap.com | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
7.5 HIGH
CVE-2026-20791 — Chargemap chargemap.com Insufficiently Protected Credentials

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

chargemap.com | Remote | Information Disclosure
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-20781 — CloudCharge cloudcharge.se Missing Authentication for Critical Function

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can …

cloudcharge.se | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
6.9 MEDIUM
CVE-2026-20733 — CloudCharge cloudcharge.se Insufficiently Protected Credentials

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

cloudcharge.se | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
8.4 HIGH
CVE-2026-1585 — "Canon IJ Scan Utility Windows Service Path Injection Vulnerability"

An unquoted Windows service executable path vulnerability in IJ Scan Utility for Windows versions 1.1.2 through 1.5.0 may allow a local attacker to execute a malicious file with the privileges of the…

| Misconfiguration
Feb 27, 2026 Mar 03, 2026
Feb 27, 2026
Mar 03, 2026
8.2 HIGH
CVE-2025-40932 — Apache::SessionX versions through 2.01 for Perl create insecure session id

Apache::SessionX versions through 2.01 for Perl create insecure session id. Apache::SessionX generates session ids insecurely. The default session id generator in Apache::SessionX::Generate::MD5 ret…

apache\ | Remote | Cryptography
Feb 27, 2026 Mar 03, 2026
Feb 27, 2026
Mar 03, 2026
5.5 MEDIUM
CVE-2026-3268 — psi-probe PSI Probe Session Attribute RemoveSessAttributeController.java access control

A vulnerability was detected in psi-probe PSI Probe up to 5.3.0. The affected element is an unknown function of the file psi-probe-core/src/main/java/psiprobe/controllers/sessions/RemoveSessAttribute…

psi_probe | Remote | Authorization
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
8.8 HIGH
CVE-2026-3265 — go2ismail Free-CRM Security API improper authorization

A vulnerability was identified in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. This affects an unknown part of the file /api/Security/ of the component Security API. The manipul…

free-crm | Remote | Authorization
Feb 26, 2026 Mar 03, 2026
Feb 26, 2026
Mar 03, 2026
8.8 HIGH
CVE-2026-3264 — go2ismail Free-CRM Administrative redirect

A vulnerability was determined in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. Affected by this issue is some unknown functionality of the component Administrative Interface. Ex…

free-crm | Remote | Misconfiguration
Feb 26, 2026 Mar 03, 2026
Feb 26, 2026
Mar 03, 2026
8.7 HIGH
CVE-2026-28280 — `osctrl-admin` has Stored Cross-Site Scripting (XSS) in On-Demand Query List

osctrl is an osquery management solution. Prior to version 0.5.0, a stored cross-site scripting (XSS) vulnerability exists in the `osctrl-admin` on-demand query list. A user with query-level permissi…

osctrl | Remote | Cross-Site Scripting
Feb 26, 2026 Feb 28, 2026
Feb 26, 2026
Feb 28, 2026
8.4 HIGH
CVE-2026-28279 — `osctrl-admin` Vulnerable to OS Command Injection via Environment Configuration

osctrl is an osquery management solution. Prior to version 0.5.0, an OS command injection vulnerability exists in the `osctrl-admin` environment configuration. An authenticated administrator can inje…

osctrl | Injection
Feb 26, 2026 Feb 28, 2026
Feb 26, 2026
Feb 28, 2026
7.5 HIGH
CVE-2026-28276 — Initiative Allows Unauthenticated Access to Uploaded Documents via Public /uploads/ Endpo…

Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions prior to 0.32.2 where uploaded documents are served from a publicly accessible /…

initiative | Remote | Authorization
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
8.1 HIGH
CVE-2026-28275 — Initiative Vulnerable to Improper Session Invalidation (JWT Remains Valid)

Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 do not invalidate previously issued JWT access tokens after a user changes their password. As a re…

initiative | Remote | Authentication
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
8.7 HIGH
CVE-2026-28274 — Initiative Vulnerable to Token Theft via Stored XSS in Document Uploads

Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to Stored Cross-Site Scripting (XSS) in the document upload functionality. Any user…

initiative | Remote | Cross-Site Scripting
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
8.8 HIGH
CVE-2026-28269 — Kiteworks Core has an OS Command Injection

Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functionality allows authenticated users to redirect command output to arbitrary file …

kiteworks | Remote | Path Traversal
Feb 26, 2026 Mar 03, 2026
Feb 26, 2026
Mar 03, 2026
7.1 HIGH
CVE-2026-28230 — In SteVe, any authenticated charger can terminate any other charger's active transaction …

SteVe is an open-source EV charging station management system. In versions up to and including 3.11.0, when a charger sends a StopTransaction message, SteVe looks up the transaction solely by transac…

steve | Remote | Authorization
Feb 26, 2026 Mar 03, 2026
Feb 26, 2026
Mar 03, 2026
6.5 MEDIUM
CVE-2026-28226 — Phishing Club has Authenticated Blind SQL Injection in GetOrphaned Recipient Listing

Phishing Club is a phishing simulation and man-in-the-middle framework. Prior to version 1.30.2, an authenticated SQL injection vulnerability exists in the GetOrphaned recipient listing endpoint in v…

phishing_club | Remote | Injection
Feb 26, 2026 Mar 03, 2026
Feb 26, 2026
Mar 03, 2026
6.5 MEDIUM
CVE-2026-28225 — Manyfold has IDOR in ModelFilesController

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Prior to version 0.133.1, the `get_model` method in `ModelFilesCon…

manyfold | Remote | Authorization
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
6.5 MEDIUM
CVE-2026-28217 — IDOR in GraphQL userCollection Query Exposes Other Users' Private Collections

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query accepts an arbitrary collection ID and returns the full collection data — includi…

hoppscotch | Remote | Authorization
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
Showing 20 of 5225 Results