Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.5 CVE-2026-48832

CVE-2026-48832_CVE-2026-48832

action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability.

SPIP SPIP CVE
LOW 2.3 CVE-2026-9398

Besen BS20 EV Charging Station BLE/WiFi authentication replay_CVE-2026-9398

A security vulnerability has been detected in Besen BS20 EV Charging Station up to 20260426. This affects an unknown part of the component BLE/WiFi...

Besen BS20 EV Charging Station 20260426 CVE
LOW 2.3 CVE-2026-9394

Besen BS20 EV Charging Station Bluetooth Low Energy weak password_CVE-2026-9394

A vulnerability was determined in Besen BS20 EV Charging Station up to 20260426. This impacts an unknown function of the component Bluetooth Low En...

Besen BS20 EV Charging Station 20260426 CVE
LOW 2.3 CVE-2026-9304

calcom cal.diy Logo API route.ts validateUrlForSSRF server-side request forgery_CVE-2026-9304

A security flaw has been discovered in calcom cal.diy up to 4.9.4. The affected element is the function validateUrlForSSRF of the file apps/web/app...

calcom cal.diy 4.9.0 CVE
LOW 3.1 CVE-2026-39967

TypeBot: Cross-Typebot Result Data Access via Missing typebotId Filter_CVE-2026-39967

TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the bot engine's the findResult query does not filter results by typebotId, allowi...

baptisteArno typebot.io < 3.16.0 CVE
LOW 3.1 CVE-2026-9249

CVE-2026-9249_CVE-2026-9249

Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted pa...

Devolutions Server 2026.1.6.0 CVE
LOW 2.6 CVE-2026-9248

CVE-2026-9248_CVE-2026-9248

Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write access to any vault to copy doc...

Devolutions Server 2026.1.6.0 CVE
LOW 2.4 CVE-2026-9247

CVE-2026-9247_CVE-2026-9247

Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealed entr...

Devolutions Server 2026.1.6.0 CVE
LOW 2.7 CVE-2026-8477

CVE-2026-8477_CVE-2026-8477

Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server allows an authenticated user ...

Devolutions Server 2026.1.6.0 CVE
LOW 2.1 CVE-2026-8353

Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in atomik theme_CVE-2026-8353

Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript tha...

Concrete CMS Concrete CMS 9.0 CVE