2026 CVE Vulnerabilities

55,810 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-3037HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker t...
CVE-2026-25721HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ...
CVE-2026-25196HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ...
CVE-2026-25105HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated atta...
CVE-2026-25037HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker...
CVE-2026-24498HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc. IpTIME T5008, EFM-Network...
CVE-2026-24452HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker...
CVE-2026-23702HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ...
CVE-2026-20764HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ...
CVE-2026-3273HIGH8.8A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function formWrlsafeset of t...
CVE-2026-25111HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ...
CVE-2026-25109HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacke...
CVE-2026-24695HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attac...
CVE-2026-24689HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker...
CVE-2026-24517HIGH7.2An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacke...
CVE-2026-21389HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ...
CVE-2026-20910HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ...
CVE-2026-20902HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attack...
CVE-2026-20742HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker...
CVE-2026-3272HIGH8.8A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromDhcpListClient of the file /goform/Dh...
CVE-2026-3270HIGH8.8A vulnerability has been found in psi-probe PSI Probe up to 5.3.0. This affects the function lookup of the file psi-prob...
CVE-2026-2597HIGH7.5Crypt::SysRandom::XS versions before 0.010 for Perl is vulnerable to a heap buffer overflow in the XS function random_by...
CVE-2026-27652HIGH7.5The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to...
CVE-2026-25778HIGH7.5The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to...
CVE-2026-25711HIGH7.5The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now