CVE-2026-101071Medium· 6.3▾ TwilightPoC availableA vulnerability was determined in Acrel Electric Unet Web Service up to 20260814. This vulnerability affects unknown code of the file /exchange/attachment/upload of the component Upload Endpoint. This manipulation of the argument File ca…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 34.7 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Exploit / PoC code exists
A vulnerability was determined in Acrel Electric Unet Web Service up to 20260814. This vulnerability affects unknown code of the file /exchange/attachment/upload of the component Upload Endpoint. This manipulation of the argument File causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-10600High· 7.3A flaw has been found in SourceCodester Online Exam Form Submission 1.0
CVE-2026-101055Medium· 5.3A security flaw has been discovered in Thinkware U3000 up to 1.02.04
CVE-2026-100906Medium· 5.3A vulnerability was detected in Eyeplus 57.0.0.0308
CVE-2026-100883Medium· 6.3A flaw has been found in Krayin laravel-crm up to 2.2.5
CVE-2025-10615Medium· 6.3A vulnerability was identified in itsourcecode E-Commerce Website 1.0
CVE-2025-10616Medium· 6.3A security flaw has been discovered in itsourcecode E-Commerce Website 1.0