High - CVE-2025-7327 - The Widget for Google Reviews plugin for...
The Widget for Google Reviews plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0.15 via the layout parameter. This makes it possible for...
Medium - CVE-2025-24002 - An unauthenticated remote attacker can use MQTT...
An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in a temporary denial-of-service for these stations...
High - CVE-2025-24003 - An unauthenticated remote attacker can use MQTT...
An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, resulting in a loss of integrity for only...
Medium - CVE-2025-24004 - A physical attacker with access to the device...
A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsecure copy to a buffer resulting in loss of integrity and a temporary...
High - CVE-2025-25268 - An unauthenticated adjacent attacker can modify...
An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting in read and write access due to missing authentication.