CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-22539MEDIUM | INFORMATION DISCLOSURE VIA CURL REQUESTS (OCPP)As the service interaction is performed without authentication, an attacker with some knowledge of the protocol could obtain information about the charger via OCPP v1.6. CWE-201Jan 7, 2026 | CVSS5.3v4.0 | EPSS0.241% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22537MEDIUM | INFORMATION DISCLOSURE WITHIN THE OPERATING SYSTEMThe lack of hardening of the system allows the user used to manage and maintain the charger to consult different files containing clear-text credentials or valuable information for an attacker. CWE-497Jan 7, 2026 | CVSS6.8v4.0 | EPSS0.109% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22536HIGH | PRIVILEGE ESCALATION VIA SUDO COMMANDThe absence of permissions control for the user XXX allows the current configuration in the sudoers file to escalate privileges without any restrictions CWE-269Jan 7, 2026 | CVSS8.6v4.0 | EPSS0.115% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22535HIGH | FRAIL SECURITY IN MQTT PROTOCOL ALLOWS AN ATTACKER MODIFY CRITICAL PARAMETERSAn attacker with the ability to interact through the network and with access credentials, could, thanks to the unsecured (unencrypted) MQTT communications protocol, write on the server topics of the board that controls the MQTT communications CWE-1366Jan 7, 2026 | CVSS8.9v4.0 | EPSS0.139% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22544HIGH | EXCHANGE OF CREDENTIALS IN CLEAR TEXTAn attacker with a network connection could detect credentials in clear text. CWE-319Jan 7, 2026 | CVSS8.7v4.0 | EPSS0.207% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22543MEDIUM | WEEK ENCODING FOR PASSWORDSThe credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials CWE-261Jan 7, 2026 | CVSS6.9v4.0 | EPSS0.185% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22542CRITICAL | DENIAL OF SERVICE FOR CONCURRENT CONNECTIONS ON TELNETAn attacker with access to the system's internal network can cause a denial of service on the system by making two concurrent connections through the Telnet service. CWE-400Jan 7, 2026 | CVSS9.2v4.0 | EPSS0.342% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22541HIGH | DENIAL OF SERVICE VIA ICMP PACKETSThe massive sending of ICMP requests causes a denial of service on one of the boards from the EVCharger that allows control the EV interfaces. Since the board must be operating correctly for the charger to also function correctly. CWE-400Jan 7, 2026 | CVSS8.2v4.0 | EPSS0.263% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |