Security Intelligence
Feed

Real-time CVE tracking, exploit analysis, and vulnerability intelligence curated for security professionals.

304 New today
65,889 Total advisories
Live Monitoring

Daily Security Trends (Last 14 Days)

60
Jun 13
68
Jun 14
443
Jun 15
630
Jun 16
464
Jun 17
3
Jun 18
352
Jun 19
56
Jun 20
104
Jun 21
317
Jun 22
294
Jun 23
355
Jun 24
376
Jun 25
226
Jun 26
Critical
High
Medium
Low

Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6 CVE-2026-55962

TLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerify_CVE-2026-55962

TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the client having sent a Certific...

wolfSSL wolfSSL 5.5.4 CVE
HIGH 7.3 CVE-2026-54479

EVoke Systems EVoke CSMS Insufficient Session Expiration_CVE-2026-54479

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same sess...

EVoke EVoke CSMS All versions CVE
HIGH 7.5 CVE-2026-50176

EVoke Systems EVoke CSMS Improper Restriction of Excessive Authentication Attempts_CVE-2026-50176

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allo...

EVoke EVoke CSMS All versions CVE
MEDIUM 6.5 CVE-2026-44622

EVoke Systems EVoke CSMS Insufficiently Protected Credentials_CVE-2026-44622

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

EVoke EVoke CSMS All versions CVE
CRITICAL 9.4 CVE-2026-40702

EVoke Systems EVoke CSMS Missing Authentication for Critical Function_CVE-2026-40702

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit ...

EVoke EVoke CSMS All versions CVE
HIGH 7.4 CVE-2026-12992

Apicurio/apicurio-registry: apicurio-registry: ssrf via wsdl4j import dereference in wsdl full validation_CVE-2026-12992

A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature....

Red Hat Red Hat build of Apicurio Registry 3 CVE
HIGH 8.5 CVE-2026-12975

Apicurio/apicurio-registry: apicurio-registry: unhardened saxparser in content-type detection leads to blind xxe / ssrf / billion-laughs dos_CVE-2026-12975

A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without enabling secure processing fea...

Red Hat Red Hat build of Apicurio Registry 3 CVE
HIGH 8.1 CVE-2026-11800

Org.keycloak:keycloak-services: keycloak: authentication bypass via jwt algorithm confusion_CVE-2026-11800

A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client c...

Red Hat Red Hat build of Keycloak 26.6 26.6.4-2 CVE
MEDIUM 6 CVE-2026-11703

Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption_CVE-2026-11703

Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for ticket-based resumption. A c...

wolfSSL wolfSSL 3.15.0 CVE