Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-20764 — Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by providing malicious input vi…

Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
9.0 HIGH
CVE-2026-3273 — Tenda F453 httpd AdvSetWrlsafeset formWrlsafeset buffer overflow

A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function formWrlsafeset of the file /goform/AdvSetWrlsafeset of the component httpd. Such manipulation of t…

f453_firmware f453 | Remote | Memory Corruption
Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
9.8 CRITICAL
CVE-2026-27647 — Mobility46 mobility46.se Insufficient Session Expiration

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in pre…

mobility46.se | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-27028 — Mobility46 mobility46.se Missing Authentication for Critical Function

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can …

mobility46.se | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-26305 — Mobility46 mobility46.se Improper Restriction of Excessive Authentication Attempts

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks…

mobility46.se | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-26290 — EV Energy ev.energy Insufficient Session Expiration

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in pre…

ev.energy | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
6.9 MEDIUM
CVE-2026-25774 — EV Energy ev.energy Insufficiently Protected Credentials

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

ev.energy | Remote | Information Disclosure
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
8.0 HIGH
CVE-2026-25195 — Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted firmw…

Feb 27, 2026 Mar 09, 2026
Feb 27, 2026
Mar 09, 2026
8.8 HIGH
CVE-2026-25111 — Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input in…

Feb 27, 2026 Mar 09, 2026
Feb 27, 2026
Mar 09, 2026
8.8 HIGH
CVE-2026-25109 — Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input …

Feb 27, 2026 Mar 09, 2026
Feb 27, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-25085 — Copeland XWEB and XWEB Pro Unexpected Status Code or Return Value

A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in which an unexpected return value from the authentication routine is later on processed as a legitimate value, resulting in a…

Feb 27, 2026 Mar 09, 2026
Feb 27, 2026
Mar 09, 2026
8.8 HIGH
CVE-2026-24695 — Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious inpu…

Feb 27, 2026 Mar 09, 2026
Feb 27, 2026
Mar 09, 2026
8.8 HIGH
CVE-2026-24689 — Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input i…

Feb 27, 2026 Mar 09, 2026
Feb 27, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-24663 — Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execution on the system by sending a crafted request t…

Feb 27, 2026 Mar 09, 2026
Feb 27, 2026
Mar 09, 2026
8.0 HIGH
CVE-2026-24517 — Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input …

Feb 27, 2026 Mar 09, 2026
Feb 27, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-24445 — EV Energy ev.energy Improper Restriction of Excessive Authentication Attempts

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks…

ev.energy | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
6.9 MEDIUM
CVE-2026-22878 — Mobility46 mobility46.se Insufficiently Protected Credentials

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

mobility46.se | Remote | Authentication
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
10.0 CRITICAL
CVE-2026-21718 — Copeland XWEB and XWEB Pro Use of a Broken or Risky Cryptographic Algorithm

An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to bypass the authentication requirement and achieve pre-authenticated code execu…

Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
8.8 HIGH
CVE-2026-21389 — Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input in…

Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
8.8 HIGH
CVE-2026-20910 — Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input in…

Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
Showing 20 of 5217 Results