2026 CVE Vulnerabilities
45,454 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21659 | CRITICAL | 9.8 | 0.9% | Feb 27, 2026 | Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in John... |
| CVE-2026-2251 | CRITICAL | 9.8 | 0.4% | Feb 27, 2026 | Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows... |
| CVE-2026-21658 | CRITICAL | 9.8 | 0.6% | Feb 27, 2026 | Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Joh... |
| CVE-2026-21657 | CRITICAL | 9.8 | 0.4% | Feb 27, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD al... |
| CVE-2026-21656 | CRITICAL | 9.8 | 0.4% | Feb 27, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD al... |
| CVE-2026-21654 | CRITICAL | 9.8 | 1.5% | Feb 27, 2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Cont... |
| CVE-2026-1626 | CRITICAL | 9.1 | 0.2% | Feb 27, 2026 | An attacker may exploit the use of weak CBC-based cipher suites in the device’s SSH service to potentially observe or ma... |
| CVE-2026-3301 | CRITICAL | 9.8 | 4.0% | Feb 27, 2026 | A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the functi... |
| CVE-2026-3289 | CRITICAL | 9.8 | 0.7% | Feb 27, 2026 | A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file Templ... |
| CVE-2026-3287 | CRITICAL | 9.8 | 0.4% | Feb 27, 2026 | A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the... |
| CVE-2026-28370 | CRITICAL | 9.1 | 0.8% | Feb 27, 2026 | In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage... |
| CVE-2026-24497 | CRITICAL | 9.8 | 0.3% | Feb 27, 2026 | Stack-based Buffer Overflow vulnerability in SimTech Systems, Inc. ThinkWise allows Remote Code Inclusion.This issue aff... |
| CVE-2026-22877 | CRITICAL | 9.1 | 0.6% | Feb 27, 2026 | An arbitrary file-read vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to... |
| CVE-2026-20797 | CRITICAL | 9.8 | 0.8% | Feb 27, 2026 | A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated att... |
| CVE-2026-27647 | CRITICAL | 9.8 | 0.3% | Feb 27, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to... |
| CVE-2026-27028 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona... |
| CVE-2026-26305 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen... |
| CVE-2026-26290 | CRITICAL | 9.8 | 0.3% | Feb 27, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to... |
| CVE-2026-25085 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in which an unexpected return value from the auth... |
| CVE-2026-24663 | CRITICAL | 9.8 | 2.3% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker... |
| CVE-2026-24445 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen... |
| CVE-2026-21718 | CRITICAL | 9.8 | 0.4% | Feb 27, 2026 | An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to ... |
| CVE-2026-3271 | CRITICAL | 9.8 | 0.8% | Feb 27, 2026 | A vulnerability was found in Tenda F453 1.0.0.3. This impacts the function fromP2pListFilter of the file /goform/P2pList... |
| CVE-2026-27772 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona... |
| CVE-2026-27767 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now