Количество 331 614
Количество 331 614
CVE-2026-22581
Rejected reason: Not used
CVE-2026-22580
Rejected reason: Not used
CVE-2026-22579
Rejected reason: Not used
CVE-2026-22578
Rejected reason: Not used
CVE-2026-22577
Rejected reason: Not used
CVE-2026-22550
OS command injection vulnerability exists in WRC-X1500GS-B and WRC-X1500GSA-B. A crafted request from a logged-in user may lead to an arbitrary OS command execution.
CVE-2026-22549
A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secrets. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-22548
When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions beyond the attacker's control can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-22544
An attacker with a network connection could detect credentials in clear text.
CVE-2026-22543
The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials
CVE-2026-22542
An attacker with access to the system's internal network can cause a denial of service on the system by making two concurrent connections through the Telnet service.
CVE-2026-22541
The massive sending of ICMP requests causes a denial of service on one of the boards from the EVCharger that allows control the EV interfaces. Since the board must be operating correctly for the charger to also function correctly.
CVE-2026-22540
The massive sending of ARP requests causes a denial of service on one board of the charger that allows control of the EV interfaces. Since the board must be operating correctly for the charger to also function correctly.
CVE-2026-22539
As the service interaction is performed without authentication, an attacker with some knowledge of the protocol could obtain information about the charger via OCPP v1.6.
CVE-2026-22537
The lack of hardening of the system allows the user used to manage and maintain the charger to consult different files containing clear-text credentials or valuable information for an attacker.
CVE-2026-22536
The absence of permissions control for the user XXX allows the current configuration in the sudoers file to escalate privileges without any restrictions
CVE-2026-22535
An attacker with the ability to interact through the network and with access credentials, could, thanks to the unsecured (unencrypted) MQTT communications protocol, write on the server topics of the board that controls the MQTT communications
CVE-2026-22522
Missing Authorization vulnerability in Munir Kamal Block Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Block Slider: from n/a through 2.2.3.
CVE-2026-22521
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in G5Theme Handmade Framework allows PHP Local File Inclusion.This issue affects Handmade Framework: from n/a through 3.9.
CVE-2026-22519
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev MediaPress allows Stored XSS.This issue affects MediaPress: from n/a through 1.6.2.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-22581 Rejected reason: Not used | около 1 месяца назад | |||
CVE-2026-22580 Rejected reason: Not used | около 1 месяца назад | |||
CVE-2026-22579 Rejected reason: Not used | около 1 месяца назад | |||
CVE-2026-22578 Rejected reason: Not used | около 1 месяца назад | |||
CVE-2026-22577 Rejected reason: Not used | около 1 месяца назад | |||
CVE-2026-22550 OS command injection vulnerability exists in WRC-X1500GS-B and WRC-X1500GSA-B. A crafted request from a logged-in user may lead to an arbitrary OS command execution. | CVSS3: 7.2 | 0% Низкий | 7 дней назад | |
CVE-2026-22549 A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secrets. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS3: 4.9 | 0% Низкий | 5 дней назад | |
CVE-2026-22548 When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions beyond the attacker's control can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS3: 5.9 | 0% Низкий | 5 дней назад | |
CVE-2026-22544 An attacker with a network connection could detect credentials in clear text. | 0% Низкий | около 1 месяца назад | ||
CVE-2026-22543 The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials | 0% Низкий | около 1 месяца назад | ||
CVE-2026-22542 An attacker with access to the system's internal network can cause a denial of service on the system by making two concurrent connections through the Telnet service. | 0% Низкий | около 1 месяца назад | ||
CVE-2026-22541 The massive sending of ICMP requests causes a denial of service on one of the boards from the EVCharger that allows control the EV interfaces. Since the board must be operating correctly for the charger to also function correctly. | 0% Низкий | около 1 месяца назад | ||
CVE-2026-22540 The massive sending of ARP requests causes a denial of service on one board of the charger that allows control of the EV interfaces. Since the board must be operating correctly for the charger to also function correctly. | 0% Низкий | около 1 месяца назад | ||
CVE-2026-22539 As the service interaction is performed without authentication, an attacker with some knowledge of the protocol could obtain information about the charger via OCPP v1.6. | 0% Низкий | около 1 месяца назад | ||
CVE-2026-22537 The lack of hardening of the system allows the user used to manage and maintain the charger to consult different files containing clear-text credentials or valuable information for an attacker. | 0% Низкий | около 1 месяца назад | ||
CVE-2026-22536 The absence of permissions control for the user XXX allows the current configuration in the sudoers file to escalate privileges without any restrictions | 0% Низкий | около 1 месяца назад | ||
CVE-2026-22535 An attacker with the ability to interact through the network and with access credentials, could, thanks to the unsecured (unencrypted) MQTT communications protocol, write on the server topics of the board that controls the MQTT communications | 0% Низкий | около 1 месяца назад | ||
CVE-2026-22522 Missing Authorization vulnerability in Munir Kamal Block Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Block Slider: from n/a through 2.2.3. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-22521 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in G5Theme Handmade Framework allows PHP Local File Inclusion.This issue affects Handmade Framework: from n/a through 3.9. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-22519 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev MediaPress allows Stored XSS.This issue affects MediaPress: from n/a through 1.6.2. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу