Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-27773 — SWITCH EV swtchenergy.com Insufficiently Protected Credentials

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

swtchenergy.com | Remote | Information Disclosure
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-27772 — EV Energy ev.energy Missing Authentication for Critical Function

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can …

ev.energy | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-27767 — SWITCH EV swtchenergy.com Missing Authentication for Critical Function

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can …

swtchenergy.com | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
7.5 HIGH
CVE-2026-27652 — CloudCharge cloudcharge.se Insufficient Session Expiration

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in pre…

cloudcharge.se | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-25945 — EV2GO ev2go.io Improper Restriction of Excessive Authentication Attempts

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks…

ev2go.io | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-25851 — Chargemap chargemap.com Missing Authentication for Critical Function

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can …

chargemap.com | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
7.5 HIGH
CVE-2026-25778 — SWITCH EV swtchenergy.com Insufficient Session Expiration

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in pre…

swtchenergy.com | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
7.5 HIGH
CVE-2026-25711 — Chargemap chargemap.com Insufficient Session Expiration

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in pre…

chargemap.com | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-25114 — CloudCharge cloudcharge.se Improper Restriction of Excessive Authentication Attempts

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks…

cloudcharge.se | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-25113 — SWITCH EV swtchenergy.com Improper Restriction of Excessive Authentication Attempts

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks…

swtchenergy.com | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
10.0 CRITICAL
CVE-2026-24731 — EV2GO ev2go.io Missing Authentication for Critical Function

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can …

ev2go.io | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
6.9 MEDIUM
CVE-2026-22890 — EV2GO ev2go.io Insufficiently Protected Credentials

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

ev2go.io | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
7.5 HIGH
CVE-2026-20895 — EV2GO ev2go.io Insufficient Session Expiration

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in pre…

ev2go.io | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-20792 — Chargemap chargemap.com Improper Restriction of Excessive Authentication Attempts

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks…

chargemap.com | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
7.5 HIGH
CVE-2026-20791 — Chargemap chargemap.com Insufficiently Protected Credentials

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

chargemap.com | Remote | Information Disclosure
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-20781 — CloudCharge cloudcharge.se Missing Authentication for Critical Function

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can …

cloudcharge.se | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
6.9 MEDIUM
CVE-2026-20733 — CloudCharge cloudcharge.se Insufficiently Protected Credentials

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

cloudcharge.se | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
8.4 HIGH
CVE-2026-1585 — "Canon IJ Scan Utility Windows Service Path Injection Vulnerability"

An unquoted Windows service executable path vulnerability in IJ Scan Utility for Windows versions 1.1.2 through 1.5.0 may allow a local attacker to execute a malicious file with the privileges of the…

| Misconfiguration
Feb 27, 2026 Mar 03, 2026
Feb 27, 2026
Mar 03, 2026
8.2 HIGH
CVE-2025-40932 — Apache::SessionX versions through 2.01 for Perl create insecure session id

Apache::SessionX versions through 2.01 for Perl create insecure session id. Apache::SessionX generates session ids insecurely. The default session id generator in Apache::SessionX::Generate::MD5 ret…

apache\ | Remote | Cryptography
Feb 27, 2026 Mar 03, 2026
Feb 27, 2026
Mar 03, 2026
5.5 MEDIUM
CVE-2026-3268 — psi-probe PSI Probe Session Attribute RemoveSessAttributeController.java access control

A vulnerability was detected in psi-probe PSI Probe up to 5.3.0. The affected element is an unknown function of the file psi-probe-core/src/main/java/psiprobe/controllers/sessions/RemoveSessAttribute…

psi_probe | Remote | Authorization
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
Showing 20 of 5068 Results