Total CVEs

138,591

Critical Severity

3,578

High Severity

12,841

Last 7 Days

1,852
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,521 - 2,540 of 3,451 CVEs
CVE-2025-11251 CRITICAL - 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows SQL Injection.This issue affects E-Commerce Platform: through 27022026. NOTE: The vendor was contacted early about this...

Vendor: Dayneks Software Industry and Trade Inc.
Product: E-Commerce Platform
Published: Feb 27, 2026
Source: NVD
CVE-2026-21660 CRITICAL - 9.8

Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, and potential misuse or system compromise This issue affects Frick ...

Vendor: Johnson Controls
Product: Frick Controls Quantum HD
Published: Feb 27, 2026
Source: NVD
CVE-2026-21659 CRITICAL - 9.8

Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Quantum HD allow an unauthenticated attacker to execute arbitrary code on the affected device, leading to full system compromise. This issue affects Fr...

Vendor: Johnson Controls
Product: Frick Controls Quantum HD
Published: Feb 27, 2026
Source: NVD
CVE-2026-2251 CRITICAL - 9.8

Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7. Please consider upgrading to FreeFlow Core version 8...

Vendor: xerox
Product: freeflow_core
Published: Feb 27, 2026
Source: NVD
CVE-2026-21658 CRITICAL - 9.8

Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact th...

Vendor: Johnson Controls
Product: Frick Controls Quantum HD
Published: Feb 27, 2026
Source: NVD
CVE-2026-21657 CRITICAL - 9.8

Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentica...

Vendor: Johnson Controls
Product: Frick Controls Quantum HD
Published: Feb 27, 2026
Source: NVD
CVE-2026-21656 CRITICAL - 9.8

Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentica...

Vendor: Johnson Controls
Product: Frick Controls Quantum HD
Published: Feb 27, 2026
Source: NVD
CVE-2026-21654 CRITICAL - 9.8

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the s...

Vendor: Johnson Controls
Product: Frick Controls Quantum HD
Published: Feb 27, 2026
Source: NVD
CVE-2025-12981 CRITICAL - 9.8

The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This is due to a broken validation check in the bundled listee-core plugin's user registration function that fails to properly sanitize the user_role parameter. This makes it possib...

Vendor: dreamstechnologies
Product: Listee
Published: Feb 27, 2026
Source: NVD
CVE-2026-3301 CRITICAL - 9.8

A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument webWlanIdx results in os command injection. T...

Vendor: totolink
Product: n300rh_firmware
Published: Feb 27, 2026
Source: NVD
CVE-2026-28370 CRITICAL - 9.1

In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under. This may result in unauthorized access to the host and further compromise of...

Vendor: OpenStack
Product: Vitrage
Published: Feb 27, 2026
Source: NVD
CVE-2026-28363 CRITICAL - 9.9

In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) in allowlist mode, leading to approval-free execution paths that were intended to require approval. Only an exact string such as --compress-program was ...

Vendor: OpenClaw
Product: OpenClaw
Published: Feb 27, 2026
Source: NVD
CVE-2026-27028 CRITICAL - 9.4

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, the...

Vendor: Mobility46
Product: mobility46.se
Published: Feb 27, 2026
Source: NVD
CVE-2026-24663 CRITICAL - 9.0

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execution on the system by sending a crafted request to the libraries installation route and injecting malicious input into the request body.

Vendor: Copeland
Product: Copeland XWEB 300D PRO, Copeland XWEB 500D PRO, Copeland XWEB 500B PRO
Published: Feb 27, 2026
Source: NVD
CVE-2026-21718 CRITICAL - 10.0

An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to bypass the authentication requirement and achieve pre-authenticated code execution on the system.

Vendor: Copeland
Product: Copeland XWEB 300D PRO, Copeland XWEB 500D PRO, Copeland XWEB 500B PRO
Published: Feb 27, 2026
Source: NVD
CVE-2026-27772 CRITICAL - 9.4

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, the...

Vendor: EV Energy
Product: ev.energy
Published: Feb 27, 2026
Source: NVD
CVE-2026-27767 CRITICAL - 9.4

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, the...

Vendor: SWITCH EV
Product: swtchenergy.com
Published: Feb 27, 2026
Source: NVD
CVE-2026-25851 CRITICAL - 9.4

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, the...

Vendor: Chargemap
Product: chargemap.com
Published: Feb 27, 2026
Source: NVD
CVE-2026-24731 CRITICAL - 9.4

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, the...

Vendor: EV2GO
Product: ev2go.io
Published: Feb 27, 2026
Source: NVD
CVE-2026-20781 CRITICAL - 9.4

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, the...

Vendor: CloudCharge
Product: cloudcharge.se
Published: Feb 27, 2026
Source: NVD