2026 CVE Vulnerabilities

70,493 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-3273HIGH8.8A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function formWrlsafeset of t...
CVE-2026-27647CRITICAL9.8The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to...
CVE-2026-27028CRITICAL9.8WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona...
CVE-2026-26305CRITICAL9.8The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen...
CVE-2026-26290CRITICAL9.8The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to...
CVE-2026-25774MEDIUM5.3Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-25195MEDIUM6.6An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attack...
CVE-2026-25111HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ...
CVE-2026-25109HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacke...
CVE-2026-25085CRITICAL9.8A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in which an unexpected return value from the auth...
CVE-2026-24695HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attac...
CVE-2026-24689HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker...
CVE-2026-24663CRITICAL9.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker...
CVE-2026-24517HIGH7.2An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacke...
CVE-2026-24445CRITICAL9.8The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen...
CVE-2026-22878MEDIUM5.3Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-21718CRITICAL9.8An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to ...
CVE-2026-21389HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ...
CVE-2026-20910HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ...
CVE-2026-20902HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attack...
CVE-2026-20742HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker...
CVE-2026-3272HIGH8.8A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromDhcpListClient of the file /goform/Dh...
CVE-2026-3271CRITICAL9.8A vulnerability was found in Tenda F453 1.0.0.3. This impacts the function fromP2pListFilter of the file /goform/P2pList...
CVE-2026-3270HIGH8.8A vulnerability has been found in psi-probe PSI Probe up to 5.3.0. This affects the function lookup of the file psi-prob...
CVE-2026-3269MEDIUM6.5A flaw has been found in psi-probe PSI Probe up to 5.3.0. The impacted element is the function handleRequestInternal of ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now