← All credits
Frank Breedijk (DIVD)
58 vulnerability records and advisories credit this contributor.
CVE-2026-102490
Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha
CVE-2026-102489
Undisclosed RCE in Zammad v6.3 and higher
CVE-2025-29757
An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous attacker with a valid account to transfer any plant into his/her account.
CVE-2025-29756
MQTT implementation in Sungrow iSolarCloud allowed users to subscribe to all data of all connected inverters
CVE-2025-22373
XSS, HTML and Style injection on login page
CVE-2025-22372
Insecure password storage in SicommNet BASEC
CVE-2025-22371
SQL-injection in admin_login_handler allows unauthenticated user to log in as an administrator in SicommNet BASEC
CVE-2025-22370
Mennekes smart/premium charges systems, SQL Injection in web configuration interface
CVE-2025-22369
Mennekes smart/premium charges systems, Arbitrary file download using ReadFile endpoint
CVE-2025-22368
Mennekes smart/premium charges systems, Command injection in sCU firmware update