2026 CVE Vulnerabilities

45,454 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-21659CRITICAL9.8Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in John...
CVE-2026-2251CRITICAL9.8Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows...
CVE-2026-21658CRITICAL9.8Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Joh...
CVE-2026-21657CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD al...
CVE-2026-21656CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD al...
CVE-2026-21654CRITICAL9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Cont...
CVE-2026-1626CRITICAL9.1An attacker may exploit the use of weak CBC-based cipher suites in the device’s SSH service to potentially observe or ma...
CVE-2026-3301CRITICAL9.8A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the functi...
CVE-2026-3289CRITICAL9.8A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file Templ...
CVE-2026-3287CRITICAL9.8A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the...
CVE-2026-28370CRITICAL9.1In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage...
CVE-2026-24497CRITICAL9.8Stack-based Buffer Overflow vulnerability in SimTech Systems, Inc. ThinkWise allows Remote Code Inclusion.This issue aff...
CVE-2026-22877CRITICAL9.1An arbitrary file-read vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to...
CVE-2026-20797CRITICAL9.8A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated att...
CVE-2026-27647CRITICAL9.8The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to...
CVE-2026-27028CRITICAL9.8WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona...
CVE-2026-26305CRITICAL9.8The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen...
CVE-2026-26290CRITICAL9.8The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to...
CVE-2026-25085CRITICAL9.8A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in which an unexpected return value from the auth...
CVE-2026-24663CRITICAL9.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker...
CVE-2026-24445CRITICAL9.8The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen...
CVE-2026-21718CRITICAL9.8An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to ...
CVE-2026-3271CRITICAL9.8A vulnerability was found in Tenda F453 1.0.0.3. This impacts the function fromP2pListFilter of the file /goform/P2pList...
CVE-2026-27772CRITICAL9.8WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona...
CVE-2026-27767CRITICAL9.8WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now