CVE Vulnerability Database
Search and browse 381,217 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22622 | HIGH | 8.8 | — | Jul 30, 2026 | Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could al... |
| CVE-2026-22621 | HIGH | 8.3 | — | Jul 30, 2026 | Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could al... |
| CVE-2026-22620 | HIGH | 8.6 | — | Jul 30, 2026 | Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unau... |
| CVE-2026-18369 | MEDIUM | 5.8 | — | Jul 30, 2026 | A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns... |
| CVE-2026-18363 | CRITICAL | 9.1 | — | Jul 30, 2026 | A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.... |
| CVE-2026-18362 | MEDIUM | 5.9 | 0.4% | Jul 30, 2026 | The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-fo... |
| CVE-2026-18361 | HIGH | 7.6 | 0.3% | Jul 30, 2026 | The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the... |
| CVE-2026-18360 | HIGH | 7.6 | 0.3% | Jul 30, 2026 | The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the... |
| CVE-2026-16971 | MEDIUM | 5.9 | 0.3% | Jul 30, 2026 | The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force a... |
| CVE-2026-16970 | MEDIUM | 4.2 | 0.2% | Jul 30, 2026 | The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Sto... |
| CVE-2026-16969 | HIGH | 7.6 | 0.3% | Jul 30, 2026 | The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the... |
| CVE-2022-4994 | — | — | — | Jul 30, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: wean fast IN from emulator_pio_in Use __... |
| CVE-2026-18353 | HIGH | 8.8 | 0.2% | Jul 30, 2026 | PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks its **unverified** `iss` claim against an issuer a... |
| CVE-2026-7849 | CRITICAL | 9.8 | 0.4% | Jul 30, 2026 | Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into ... |
| CVE-2026-44108 | CRITICAL | 9.8 | 0.5% | Jul 30, 2026 | Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system sh... |
| CVE-2026-44107 | HIGH | 8.7 | 0.3% | Jul 30, 2026 | A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus f... |
| CVE-2026-44106 | HIGH | 8.5 | 0.2% | Jul 30, 2026 | A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to exec... |
| CVE-2026-44105 | MEDIUM | 6.6 | 0.1% | Jul 30, 2026 | The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local a... |
| CVE-2026-44104 | CRITICAL | 9.8 | 0.2% | Jul 30, 2026 | The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryp... |
| CVE-2026-44103 | MEDIUM | 6.9 | 0.2% | Jul 30, 2026 | An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore ... |
| CVE-2026-44102 | MEDIUM | 6.9 | 0.2% | Jul 30, 2026 | An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid f... |
| CVE-2026-44101 | CRITICAL | 9.8 | 0.4% | Jul 30, 2026 | Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the ... |
| CVE-2026-44100 | CRITICAL | 9.4 | 0.3% | Jul 30, 2026 | The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to di... |
| CVE-2026-44099 | HIGH | 8.5 | 0.2% | Jul 30, 2026 | A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary... |
| CVE-2026-44098 | HIGH | 8.8 | 1.4% | Jul 30, 2026 | This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to p... |
