VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,287 CVE recordsPage 369 of 1286 · EPSS data 2026.08.11
ReviewHigh
CVE-2026-57371

denishua WPJAM Basic

Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a through <= 7.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57369

themifyme Themify Builder

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Builder themify-builder allows Reflected XSS.This issue affects Themify Builder: from n/a through <= 7.7.4.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57368

NooTheme Jobmonster

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster noo-jobmonster allows Reflected XSS.This issue affects Jobmonster: from n/a through <= 4.8.5.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57363

QuantumCloud ChatBot

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot chatbot allows Stored XSS.This issue affects ChatBot: from n/a through <= 8.3.7.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-41041

Apache Software Foundation Apache Gravitino, gravitino

URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before 1.2.1. Users are recommended to upgrade to version 1.2.1, which fixes the issue.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-22103

EVbee DC-80

The NPC start endpoint on the web server at port 8090 is vulnerable to command injection.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-22102

EVbee DC-80

A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint accepts the filename parameter in the Content-Disposition header without verification. This can be used to cause a denial of service by overwriting system files, or remote-code-execution by overwriting shell-scripts which execution can be triggered through other means.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-22100

EVbee DC-80

The OCPP DataTransfer message `ReserveLogin` is vulnerable to command injection. By manipulating the data value, arbitrary OS commands can be executed as root.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-22099

EVbee DC-80

The charging station does not require authentication for Bluetooth commands to perform actions. The functionality exposed includes sensitive information leakage, triggering reboots, or pushing a firmware update URL.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-22098

EVbee DC-80

Various sensitive information such as passwords and charging card UIDs are written to log files.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-22097

EVbee DC-80

The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the firmware update capability to upload arbitrary files which can then lead to arbitrary code execution.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-22096

EVbee DC-80

The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such as configured passwords, or uploading files through different endpoints.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-22095

EVbee DC-80

The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-22093

EVbee EVbee Service

The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided by the server. This allows an attacker on the network path between the app and EVbee server to intercept and manipulate the communication between the app and server. The traffic is weakly encrypted using RC4 with a hardcoded key, which allows an attacker to gain access to the communication. Part of this communication involves access codes to charging stations. This issue affects EVbee Service: v1.4.101.00.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-15548

Shibby Tomato

A security vulnerability has been detected in Shibby Tomato up to 1.28.0000. This vulnerability affects the function sub_407220 of the file /usr/sbin/httpd of the component DNS List Rendering. The manipulation leads to stack-based buffer overflow. The attack is possible to be carried out remotely. This project is superseded by FreshTomato.

The CVSS severity warrants an early asset and exposure review.