2026 CVE Vulnerabilities
70,493 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3273 | HIGH | 8.8 | 0.6% | Feb 27, 2026 | A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function formWrlsafeset of t... |
| CVE-2026-27647 | CRITICAL | 9.8 | 0.3% | Feb 27, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to... |
| CVE-2026-27028 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona... |
| CVE-2026-26305 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen... |
| CVE-2026-26290 | CRITICAL | 9.8 | 0.3% | Feb 27, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to... |
| CVE-2026-25774 | MEDIUM | 5.3 | 0.3% | Feb 27, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. |
| CVE-2026-25195 | MEDIUM | 6.6 | 1.4% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attack... |
| CVE-2026-25111 | HIGH | 8.8 | 1.5% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ... |
| CVE-2026-25109 | HIGH | 8.8 | 1.5% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacke... |
| CVE-2026-25085 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in which an unexpected return value from the auth... |
| CVE-2026-24695 | HIGH | 8.8 | 1.5% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attac... |
| CVE-2026-24689 | HIGH | 8.8 | 1.5% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker... |
| CVE-2026-24663 | CRITICAL | 9.8 | 2.3% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker... |
| CVE-2026-24517 | HIGH | 7.2 | 1.6% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacke... |
| CVE-2026-24445 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen... |
| CVE-2026-22878 | MEDIUM | 5.3 | 0.3% | Feb 27, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. |
| CVE-2026-21718 | CRITICAL | 9.8 | 0.4% | Feb 27, 2026 | An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to ... |
| CVE-2026-21389 | HIGH | 8.8 | 1.5% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ... |
| CVE-2026-20910 | HIGH | 8.8 | 1.5% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ... |
| CVE-2026-20902 | HIGH | 8.8 | 1.5% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attack... |
| CVE-2026-20742 | HIGH | 8.8 | 1.5% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker... |
| CVE-2026-3272 | HIGH | 8.8 | 0.7% | Feb 27, 2026 | A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromDhcpListClient of the file /goform/Dh... |
| CVE-2026-3271 | CRITICAL | 9.8 | 0.8% | Feb 27, 2026 | A vulnerability was found in Tenda F453 1.0.0.3. This impacts the function fromP2pListFilter of the file /goform/P2pList... |
| CVE-2026-3270 | HIGH | 8.8 | 0.4% | Feb 27, 2026 | A vulnerability has been found in psi-probe PSI Probe up to 5.3.0. This affects the function lookup of the file psi-prob... |
| CVE-2026-3269 | MEDIUM | 6.5 | 0.6% | Feb 27, 2026 | A flaw has been found in psi-probe PSI Probe up to 5.3.0. The impacted element is the function handleRequestInternal of ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now