CVE-2026-93474Medium· 6.5▾ SunlitCharging station authentication identifiers are publicly accessible via web-based mapping platforms.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-97363High· 7.5The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests
CVE-2026-95102Critical· 9.4WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations
CVE-2026-97212High· 7.3The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier
CVE-2025-67732Medium· 6.5Dify is an open-source LLM app development platform
CVE-2020-5404Medium· 5.9The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain
CVE-2019-11284High· 8.6Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones