2026 CVE Vulnerabilities

51,113 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44108CRITICAL9.8Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system sh...
CVE-2026-44107HIGH8.7A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus f...
CVE-2026-44106HIGH8.5A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to exec...
CVE-2026-44105MEDIUM6.6The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local a...
CVE-2026-44104CRITICAL9.8The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryp...
CVE-2026-44103MEDIUM6.9An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore ...
CVE-2026-44102MEDIUM6.9An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid f...
CVE-2026-44101CRITICAL9.8Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the ...
CVE-2026-44100CRITICAL9.4The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to di...
CVE-2026-44099HIGH8.5A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary...
CVE-2026-44098HIGH8.8This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to p...
CVE-2026-44097HIGH7.1A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for fi...
CVE-2026-44096HIGH8.5A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, re...
CVE-2026-44095HIGH8.5A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to ex...
CVE-2026-44094HIGH8.6An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configur...
CVE-2026-44093HIGH8.5A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user t...
CVE-2026-44092CRITICAL9.1An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not vali...
CVE-2026-44091CRITICAL9.1An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configura...
CVE-2026-44090CRITICAL9.8Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected fr...
CVE-2026-13584HIGH7.1Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Ele...
CVE-2026-64635MEDIUM5.3Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an...
CVE-2026-59328MEDIUM4.2Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browse...
CVE-2026-59327MEDIUM4.4Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string...
CVE-2026-59326LOW3.3The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment vari...
CVE-2026-58066CRITICAL9.8Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now