Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,650
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,301 - 10,320 of 13,241 CVEs
CVE-2026-20910 HIGH - 8.0

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field of the firmware update update action to achieve remote code execution.

Vendor: Copeland
Product: Copeland XWEB 300D PRO, Copeland XWEB 500D PRO, Copeland XWEB 500B PRO
Published: Feb 27, 2026
Source: NVD
CVE-2026-20902 HIGH - 8.0

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the map filename field during the map upload action of the parameters route.

Vendor: Copeland
Product: Copeland XWEB 300D PRO, Copeland XWEB 500D PRO, Copeland XWEB 500B PRO
Published: Feb 27, 2026
Source: NVD
CVE-2026-20742 HIGH - 8.0

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the templates route.

Vendor: Copeland
Product: Copeland XWEB 300D PRO, Copeland XWEB 500D PRO, Copeland XWEB 500B PRO
Published: Feb 27, 2026
Source: NVD
CVE-2026-3272 HIGH - 8.8

A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd. This manipulation of the argument page causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly dis...

Vendor: tenda
Product: f453_firmware
Published: Feb 27, 2026
Source: NVD
CVE-2026-3271 HIGH - 8.8

A vulnerability was found in Tenda F453 1.0.0.3. This impacts the function fromP2pListFilter of the file /goform/P2pListFilterof of the component httpd. The manipulation of the argument page results in buffer overflow. The attack may be launched remotely. The exploit has been made public and could b...

Vendor: tenda
Product: f453_firmware
Published: Feb 27, 2026
Source: NVD
CVE-2026-2597 HIGH - 7.5

Crypt::SysRandom::XS versions before 0.010 for Perl is vulnerable to a heap buffer overflow in the XS function random_bytes(). The function does not validate that the length parameter is non-negative. If a negative value (e.g. -1) is supplied, the expression length + 1u causes an integer wraparound...

Vendor: leont
Product: crypt\
Published: Feb 27, 2026
Source: NVD
CVE-2026-27652 HIGH - 7.3

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent conn...

Vendor: CloudCharge
Product: cloudcharge.se
Published: Feb 27, 2026
Source: NVD
CVE-2026-25945 HIGH - 7.5

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain...

Vendor: EV2GO
Product: ev2go.io
Published: Feb 27, 2026
Source: NVD
CVE-2026-25778 HIGH - 7.3

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent conn...

Vendor: SWITCH EV
Product: swtchenergy.com
Published: Feb 27, 2026
Source: NVD
CVE-2026-25711 HIGH - 7.3

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent conn...

Vendor: Chargemap
Product: chargemap.com
Published: Feb 27, 2026
Source: NVD
CVE-2026-25114 HIGH - 7.5

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain...

Vendor: CloudCharge
Product: cloudcharge.se
Published: Feb 27, 2026
Source: NVD
CVE-2026-25113 HIGH - 7.5

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain...

Vendor: SWITCH EV
Product: swtchenergy.com
Published: Feb 27, 2026
Source: NVD
CVE-2026-20895 HIGH - 7.3

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent conn...

Vendor: EV2GO
Product: ev2go.io
Published: Feb 27, 2026
Source: NVD
CVE-2026-20792 HIGH - 7.5

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or misrouting legitimate charger telemetry, or conduct brute-force attacks to gain ...

Vendor: Chargemap
Product: chargemap.com
Published: Feb 27, 2026
Source: NVD
CVE-2025-40932 HIGH - 8.2

Apache::SessionX versions through 2.01 for Perl create insecure session id. Apache::SessionX generates session ids insecurely. The default session id generator in Apache::SessionX::Generate::MD5 returns a MD5 hash seeded with the built-in rand() function, the epoch time, and the PID. The PID will c...

Vendor: GRICHTER
Product: Apache::SessionX
Published: Feb 27, 2026
Source: NVD
CVE-2026-28279 HIGH - 7.3

osctrl is an osquery management solution. Prior to version 0.5.0, an OS command injection vulnerability exists in the `osctrl-admin` environment configuration. An authenticated administrator can inject arbitrary shell commands via the hostname parameter when creating or editing environments. These c...

Vendor: jmpsec
Product: osctrl
Published: Feb 26, 2026
Source: NVD
CVE-2026-28276 HIGH - 7.5

Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions prior to 0.32.2 where uploaded documents are served from a publicly accessible /uploads/ directory without any authentication or authorization checks. Any uploaded file can be acces...

Vendor: Morelitea
Product: initiative
Published: Feb 26, 2026
Source: NVD
CVE-2026-28275 HIGH - 8.1

Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 do not invalidate previously issued JWT access tokens after a user changes their password. As a result, older tokens remain valid until expiration and can still be used to access protected API endpoi...

Vendor: Morelitea
Product: initiative
Published: Feb 26, 2026
Source: NVD
CVE-2026-28274 HIGH - 8.7

Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to Stored Cross-Site Scripting (XSS) in the document upload functionality. Any user with upload permissions within the "Initiatives" section can upload a malicious `.html` or...

Vendor: Morelitea
Product: initiative
Published: Feb 26, 2026
Source: NVD
CVE-2026-28216 HIGH - 8.3

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify or delete another user's personal environment by ID. `user-environments.resolver.ts:82-109`, `updateUserEnvironment` mutation uses `@UseGuards(GqlAuthGuard)` but is missing the...

Vendor: hoppscotch
Product: hoppscotch
Published: Feb 26, 2026
Source: NVD