CVE Feed

    Dashboard / CVE

    8
    High

    CVE-2026-3037

    Last Modified: 17 Apr 2026

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by modifying malicious input injected into the MBird SMS service URL and/or code via the utility route which is later processed during system setup, leading to remote code execution.

    Published: 27 Feb 2026
    4.3
    Medium

    CVE-2026-20797

    Last Modified: 10 May 2026

    A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to cause stack corruption and a termination of the program.

    Published: 27 Feb 2026
    7.4
    High

    CVE-2026-3274

    Last Modified: 16 Apr 2026

    A security flaw has been discovered in Tenda F453 1.0.0.3. Affected by this issue is the function frmL7ProtForm of the file /goform/L7Prot of the component httpd. Performing a manipulation of the argument page results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

    Published: 27 Feb 2026
    3.7
    Low

    CVE-2026-22877

    Last Modified: 18 Apr 2026

    An arbitrary file-read vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to read arbitrary files on the system, and potentially causing a denial-of-service attack.

    Published: 27 Feb 2026
    8
    High

    CVE-2026-25037

    Last Modified: 16 Apr 2026

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by configuring a maliciously crafted LCD state which is later processed during system setup, enabling remote code execution.

    Published: 27 Feb 2026
    8
    High

    CVE-2026-25196

    Last Modified: 16 Apr 2026

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the Wi-Fi SSID and/or password fields can lead to remote code execution when the configuration is processed.

    Published: 27 Feb 2026
    8
    High

    CVE-2026-20764

    Last Modified: 16 Apr 2026

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by providing malicious input via the device hostname configuration which is later processed during system setup, resulting in remote code execution.

    Published: 27 Feb 2026
    8
    High

    CVE-2026-25721

    Last Modified: 16 Apr 2026

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the server username and/or password fields of the restore action in the API V1 route.

    Published: 27 Feb 2026
    8
    High

    CVE-2026-23702

    Last Modified: 17 Apr 2026

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by sending malicious input injected into the server username field of the import preconfiguration action in the API V1 route.

    Published: 27 Feb 2026
    8
    High

    CVE-2026-24452

    Last Modified: 17 Apr 2026

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted template file to the devices route.

    Published: 27 Feb 2026
    8
    High

    CVE-2026-25105

    Last Modified: 16 Apr 2026

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into parameters of the Modbus command tool in the debug route.

    Published: 27 Feb 2026
    8
    High

    CVE-2026-24695

    Last Modified: 16 Apr 2026

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into OpenSSL argument fields within requests sent to the utility route, leading to remote code execution.

    Published: 27 Feb 2026
    8
    High

    CVE-2026-20902

    Last Modified: 18 Apr 2026

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the map filename field during the map upload action of the parameters route.

    Published: 27 Feb 2026
    8
    High

    CVE-2026-25109

    Last Modified: 4 Jun 2026

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field when accessing the get setup route.

    Published: 27 Feb 2026
    8
    High

    CVE-2026-24689

    Last Modified: 16 Apr 2026

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field of the firmware update apply action.

    Published: 27 Feb 2026
    8
    High

    CVE-2026-20910

    Last Modified: 4 Jun 2026

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field of the firmware update action to achieve remote code execution.

    Published: 27 Feb 2026
    8
    High

    CVE-2026-25195

    Last Modified: 16 Apr 2026

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted firmware update file via the firmware update route.

    Published: 27 Feb 2026
    8
    High

    CVE-2026-24517

    Last Modified: 16 Apr 2026

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the firmware update route.

    Published: 27 Feb 2026
    8
    High

    CVE-2026-20742

    Last Modified: 17 Apr 2026

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the templates route.

    Published: 27 Feb 2026
    8
    High

    CVE-2026-25111

    Last Modified: 16 Apr 2026

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the restore route.

    Published: 27 Feb 2026
    8
    High

    CVE-2026-21389

    Last Modified: 16 Apr 2026

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the request body sent to the contacts import route.

    Published: 27 Feb 2026
    9
    Critical

    CVE-2026-24663

    Last Modified: 18 Apr 2026

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execution on the system by sending a crafted request to the libraries installation route and injecting malicious input into the request body.

    Published: 27 Feb 2026
    10
    Critical

    CVE-2026-21718

    Last Modified: 17 Apr 2026

    An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to bypass the authentication requirement and achieve pre-authenticated code execution on the system.

    Published: 27 Feb 2026
    8.6
    High

    CVE-2026-25085

    Last Modified: 16 Apr 2026

    A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in which an unexpected return value from the authentication routine is later on processed as a legitimate value, resulting in an authentication bypass.

    Published: 27 Feb 2026
    7.4
    High

    CVE-2026-3273

    Last Modified: 16 Apr 2026

    A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function formWrlsafeset of the file /goform/AdvSetWrlsafeset of the component httpd. Such manipulation of the argument mit_ssid_index leads to buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.

    Published: 27 Feb 2026
    6.9
    Medium

    CVE-2026-22878

    Last Modified: 17 Apr 2026

    Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

    Published: 27 Feb 2026
    6.9
    Medium

    CVE-2026-27647

    Last Modified: 16 Apr 2026

    The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connection displaces the legitimate charging station and receives backend commands intended for that station. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.

    Published: 27 Feb 2026
    8.7
    High

    CVE-2026-26305

    Last Modified: 16 Apr 2026

    The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain unauthorized access.

    Published: 27 Feb 2026
    9.3
    Critical

    CVE-2026-27028

    Last Modified: 16 Apr 2026

    WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP commands as a legitimate charger. Given that no authentication is required, this can lead to privilege escalation, unauthorized control of charging infrastructure, and corruption of charging network data reported to the backend.

    Published: 27 Feb 2026
    6.5
    Medium

    CVE-2021-4456

    Last Modified: 3 Mar 2026

    Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may have unspecified impact. The functions `addr2cidr` and `cidrlookup` may return leading zeros in a CIDR string, which may in turn be parsed as octal numbers by subsequent users. In some cases an attacker may be able to leverage this to bypass access controls based on IP addresses. The documentation advises validating untrusted CIDR strings with the `cidrvalidate` function. However, this mitigation is optional and not enforced by default. In practice, users may call `addr2cidr` or `cidrlookup` with untrusted input and without validation, incorrectly assuming that this is safe.

    Published: 27 Feb 2026
    6.9
    Medium

    CVE-2026-25774

    Last Modified: 15 Apr 2026

    Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

    Published: 27 Feb 2026
    6.9
    Medium

    CVE-2026-26290

    Last Modified: 16 Apr 2026

    The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connection displaces the legitimate charging station and receives backend commands intended for that station. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.

    Published: 27 Feb 2026
    8.7
    High

    CVE-2026-24445

    Last Modified: 16 Apr 2026

    The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain unauthorized access.

    Published: 27 Feb 2026
    9.3
    Critical

    CVE-2026-27772

    Last Modified: 16 Apr 2026

    WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP commands as a legitimate charger. Given that no authentication is required, this can lead to privilege escalation, unauthorized control of charging infrastructure, and corruption of charging network data reported to the backend.

    Published: 27 Feb 2026
    6.9
    Medium

    CVE-2026-27773

    Last Modified: 17 Apr 2026

    Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

    Published: 27 Feb 2026
    6.9
    Medium

    CVE-2026-25778

    Last Modified: 18 Apr 2026

    The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connection displaces the legitimate charging station and receives backend commands intended for that station. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.

    Published: 27 Feb 2026
    7.4
    High

    CVE-2026-3272

    Last Modified: 16 Apr 2026

    A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd. This manipulation of the argument page causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

    Published: 27 Feb 2026
    7.4
    High

    CVE-2026-3271

    Last Modified: 17 Apr 2026

    A vulnerability was found in Tenda F453 1.0.0.3. This impacts the function fromP2pListFilter of the file /goform/P2pListFilterof of the component httpd. The manipulation of the argument page results in buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.

    Published: 27 Feb 2026
    8.3
    High

    CVE-2026-26862

    Last Modified: 16 Apr 2026

    CleverTap Web SDK version 1.15.2 and earlier is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage in the Visual Builder module. The origin validation in src/modules/visualBuilder/pageBuilder.js (lines 56-60) uses the includes() method to verify the originUrl contains "dashboard.clevertap.com", which can be bypassed by an attacker using a crafted subdomain

    Published: 27 Feb 2026
    8.3
    High

    CVE-2026-26861

    Last Modified: 16 Apr 2026

    CleverTap Web SDK version 1.15.2 and earlier is vulnerable to Cross-Site Scripting (XSS) via window.postMessage. The handleCustomHtmlPreviewPostMessageEvent function in src/util/campaignRender/nativeDisplay.js performs insufficient origin validation using the includes() method, which can be bypassed by an attacker using a subdomain

    Published: 27 Feb 2026
    8.7
    High

    CVE-2025-69437

    Last Modified: 5 Mar 2026

    PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the backend CmsFileUtils.java. If a user uploads a PDF file containing a malicious payload to the system and views it, the embedded JavaScript payload can be triggered, resulting in issues such as credential theft, arbitrary API execution, and other security concerns. This vulnerability affects all file upload endpoint, including /cmsTemplate/save, /file/doUpload, /cmsTemplate/doUpload, /file/doBatchUpload, /cmsWebFile/doUpload, etc.

    Published: 27 Feb 2026
    8.7
    High

    CVE-2026-25113

    Last Modified: 16 Apr 2026

    The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain unauthorized access.

    Published: 26 Feb 2026
    9.3
    Critical

    CVE-2026-27767

    Last Modified: 17 Apr 2026

    WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP commands as a legitimate charger. Given that no authentication is required, this can lead to privilege escalation, unauthorized control of charging infrastructure, and corruption of charging network data reported to the backend.

    Published: 26 Feb 2026
    6.9
    Medium

    CVE-2026-22890

    Last Modified: 17 Apr 2026

    Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

    Published: 26 Feb 2026
    6.9
    Medium

    CVE-2026-20895

    Last Modified: 17 Apr 2026

    The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connection displaces the legitimate charging station and receives backend commands intended for that station. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.

    Published: 26 Feb 2026
    8.7
    High

    CVE-2026-25945

    Last Modified: 17 Apr 2026

    The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain unauthorized access.

    Published: 26 Feb 2026
    9.3
    Critical

    CVE-2026-24731

    Last Modified: 16 Apr 2026

    WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP commands as a legitimate charger. Given that no authentication is required, this can lead to privilege escalation, unauthorized control of charging infrastructure, and corruption of charging network data reported to the backend.

    Published: 26 Feb 2026
    8.4
    High

    CVE-2026-1585

    Last Modified: 16 Apr 2026

    An unquoted Windows service executable path vulnerability in IJ Scan Utility for Windows versions 1.1.2 through 1.5.0 may allow a local attacker to execute a malicious file with the privileges of the affected service.

    Published: 26 Feb 2026
    6.9
    Medium

    CVE-2026-20733

    Last Modified: 16 Apr 2026

    Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

    Published: 26 Feb 2026
    6.9
    Medium

    CVE-2026-27652

    Last Modified: 16 Apr 2026

    The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connection displaces the legitimate charging station and receives backend commands intended for that station. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.

    Published: 26 Feb 2026