8

CVSS3.1

CVE-2026-24689 - Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field of the firmware update apply action.

๐Ÿ“… Published: Feb. 27, 2026, 12:47 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 3:45 p.m.

8

CVSS3.1

CVE-2026-20910 - Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field of the firmware update update action to achieve remote code execution.

๐Ÿ“… Published: Feb. 27, 2026, 12:46 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 3:45 p.m.

8

CVSS3.1

CVE-2026-25195 - Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted firmware update file via the firmware update route.

๐Ÿ“… Published: Feb. 27, 2026, 12:45 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 3:45 p.m.

8

CVSS3.1

CVE-2026-24517 - Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the firmware update route.

๐Ÿ“… Published: Feb. 27, 2026, 12:43 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 3:45 p.m.

8

CVSS3.1

CVE-2026-20742 - Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the templates route.

๐Ÿ“… Published: Feb. 27, 2026, 12:42 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:15 p.m.

8

CVSS3.1

CVE-2026-25111 - Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the restore route.

๐Ÿ“… Published: Feb. 27, 2026, 12:40 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 3:45 p.m.

8

CVSS3.1

CVE-2026-21389 - Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the request body sent to the contacts import route.

๐Ÿ“… Published: Feb. 27, 2026, 12:38 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 3:45 p.m.

9

CVSS3.1

CVE-2026-24663 - Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execution on the system by sending a crafted request to the libraries installation route and injecting malicious input into the request body.

๐Ÿ“… Published: Feb. 27, 2026, 12:36 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 10:30 a.m.

10

CVSS3.1

CVE-2026-21718 - Copeland XWEB and XWEB Pro Use of a Broken or Risky Cryptographic Algorithm

An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to bypass the authentication requirement and achieve pre-authenticated code execution on the system.

๐Ÿ“… Published: Feb. 27, 2026, 12:34 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:15 p.m.

8.6

CVSS3.1

CVE-2026-25085 - Copeland XWEB and XWEB Pro Unexpected Status Code or Return Value

A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in which an unexpected return value from the authentication routine is later on processed as a legitimate value, resulting in an authentication bypass.

๐Ÿ“… Published: Feb. 27, 2026, 12:33 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 3:45 p.m.
Total resulsts: 349182
Page 1412 of 34,919
ยซ previous page ยป next page
Filters