2026 CVE Vulnerabilities
55,810 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3037 | HIGH | 8.8 | 1.9% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker t... |
| CVE-2026-25721 | HIGH | 8.8 | 1.9% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ... |
| CVE-2026-25196 | HIGH | 8.8 | 1.9% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ... |
| CVE-2026-25105 | HIGH | 8.8 | 1.9% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated atta... |
| CVE-2026-25037 | HIGH | 8.8 | 1.9% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker... |
| CVE-2026-24498 | HIGH | 7.5 | 0.4% | Feb 27, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc. IpTIME T5008, EFM-Network... |
| CVE-2026-24452 | HIGH | 8.8 | 1.9% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker... |
| CVE-2026-23702 | HIGH | 8.8 | 1.9% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ... |
| CVE-2026-20764 | HIGH | 8.8 | 1.9% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ... |
| CVE-2026-3273 | HIGH | 8.8 | 0.6% | Feb 27, 2026 | A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function formWrlsafeset of t... |
| CVE-2026-25111 | HIGH | 8.8 | 1.5% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ... |
| CVE-2026-25109 | HIGH | 8.8 | 1.5% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacke... |
| CVE-2026-24695 | HIGH | 8.8 | 1.5% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attac... |
| CVE-2026-24689 | HIGH | 8.8 | 1.5% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker... |
| CVE-2026-24517 | HIGH | 7.2 | 1.6% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacke... |
| CVE-2026-21389 | HIGH | 8.8 | 1.5% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ... |
| CVE-2026-20910 | HIGH | 8.8 | 1.5% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ... |
| CVE-2026-20902 | HIGH | 8.8 | 1.5% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attack... |
| CVE-2026-20742 | HIGH | 8.8 | 1.5% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker... |
| CVE-2026-3272 | HIGH | 8.8 | 0.7% | Feb 27, 2026 | A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromDhcpListClient of the file /goform/Dh... |
| CVE-2026-3270 | HIGH | 8.8 | 0.4% | Feb 27, 2026 | A vulnerability has been found in psi-probe PSI Probe up to 5.3.0. This affects the function lookup of the file psi-prob... |
| CVE-2026-2597 | HIGH | 7.5 | 0.3% | Feb 27, 2026 | Crypt::SysRandom::XS versions before 0.010 for Perl is vulnerable to a heap buffer overflow in the XS function random_by... |
| CVE-2026-27652 | HIGH | 7.5 | 0.3% | Feb 27, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to... |
| CVE-2026-25778 | HIGH | 7.5 | 0.3% | Feb 27, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to... |
| CVE-2026-25711 | HIGH | 7.5 | 0.3% | Feb 27, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now