CVE-2026-102458Critical· 9.8▾ MidnightEasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102455Critical· 9.8EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability
CVE-2026-102457Medium· 6.5EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability
CVE-2026-102459Medium· 6.1EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability
CVE-2026-102456Medium· 6.5EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability
CVE-2026-102454High· 7.2EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability
CVE-2025-9815High· 7.8A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS