Skip to the content.
Home
/
DIVD CSIRT
Making the internet safer through Coordinated Vulnerability Disclosure
Menu
Home
DIVD
CSIRT
Cases
DIVD-2026-00010 - Improper Access Control in Hashtopolis Server
An improper access control vulnerability in the Hashtopolis server chunk ac...
DIVD-2026-00007 - Victim Notification Operation Endgame - S03E03 & S03E04
The DIVD is notifying victims of the SocGholish malware and the StealC and ...
DIVD-2026-00006 - Vulnerability found in DIVD App VerySecureApp
The VerySecureApp made by DIVD using Mendix Studio Pro 11.8.0 Beta allows u...
DIVD-2026-00005 - Salesforce Experience Cloud – Data Exposure via Misconfig
DIVD is researching Salesforce Experience Cloud applications exposing sensi...
DIVD-2026-00003 - Mendix Applications – Data Exposure due to Authorization
DIVD is researching Mendix applications exposing sensitive data due to auth...
DIVD-2026-00002 - DIVD-2026-00002 – Ivanti Endpoint Manager Mobile Vulnerab
Two critical vulnerabilities in Ivanti Endpoint Manager Mobile allow unauth...
DIVD-2026-00001 - DIVD-2026-00001 – EVbee Service App and DC Quick Charging
Multiple vulnerabilities in EVbee Service App and DC Quick Charging Station...
DIVD-2025-00042 - React2shell vulnerability
A vulnerability in React Server components allow unauthorized access via Re...
DIVD-2025-00041 - Victim Notification Operation Endgame S03E01
DIVD is notifying victims of the various infostealer malware strains from i...
DIVD-2025-00040 - Oracle E-Business Suite Vulnerabilities
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Busin...
DIVD-2025-00039 - Cisco ASA WebVPN Vulnerabilities
Multiple vulnerabilities in Cisco ASA WebVPN could allow attackers to bypas...
DIVD-2025-00038 - Found webshells in FreePBX due to RCE vulnerability
FreePBX has assigned CVE-2025-57819 to vulnerabilities in its administrator...
DIVD-2025-00037 - Critical vulnerabilities in Citrix ADC and Gateway system
Citrix has released security updates for vulnerabilities in NetScaler ADC a...
DIVD-2025-00035 - Sharepoint Mass-Exploitation (ToolShell) through CVE-2025
Threat actors are targeting Sharepoint installations with CVE-2025-53770. I...
DIVD-2025-00034 - Remote Code Execution in IBM WebSphere version 8.5 and 9.
A critical vulnerability in IBM WebSphere was discovered in versions 8.5 an...
DIVD-2025-00033 - Remote Code Execution in GeoServer versions below 2.27.0,
A critical vulnerability in GeoServer was discovered in versions below 2.27...
DIVD-2025-00032 - Unauthenticated Arbitrary Remote Code Execution in Pterod
A critical vulnerability in Pterodactyl was discovered in versions below 1....
DIVD-2025-00031 - Critical vulnerabilities in Citrix ADC and Gateway system
Citrix has released security updates for vulnerabilities in Citrix ADC and ...
DIVD-2025-00022 - SolarEdge SE3680H and SolarEdge Monitoring Platform vulne
Vulnerabilities found in SolarEdge SE3680H and SolarEdge Monitoring Platfor...
DIVD-2025-00019 - Unauthenticated file upload in Visual Composer (VCFRAMEWO
SAP NetWeaver Visual Composer Metadata Uploader lacks proper authorization,...
All cases
CVEs
CVE-2026-22104 - Improper access control in Hashtopolis server chunk activity...
CVE-2026-22103 - Command injection in NPC start web endpoint...
CVE-2026-22102 - Arbitrary file overwrite through certificate update function...
CVE-2026-22100 - Comnand injection in OCPP ReserveLogin message...
CVE-2026-22099 - Missing authentication for Bluetooth communication...
CVE-2026-22098 - Sensitive information is written to logs...
CVE-2026-22097 - Missing firmware validation allows remote code execution...
CVE-2026-22096 - Missing authentication for webserver endpoints...
CVE-2026-22095 - Command injection in diagnosis web endpoint...
CVE-2026-22093 - Adversary-in-the-Middle (AitM) attack vulnerability in EVbee...
More...
CNA
Stolen credentials
Blog
2026-07-31 : CyberAuditWeb and videx-legacy-ssl full disclosure...
2026-07-30 : Visioweb.js...
2026-07-30 : Cloudflow...
2026-07-27 : Six vulnerabilities in Enphase IQ Gateway devices...
2026-07-17 : White Rabbit Switch full disclosure...
2026-07-17 : Axiell Iguana CMS full disclosure...
2026-07-16 : Mennekes Smart - charging stations full disclosure...
2026-07-16 : SOPlanning Online Planning tool full disclosure...
2026-06-25 : StealC data available from Operation Endgame S03E04...
2025-11-13 : Data available from Operation Endgame S03E01...
More...
Donate
Search...
RSS
Contact
Search