Vulnerability index

Browse CVEs

31 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-25196

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-25721

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-3037

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-25037

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execu…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-25105

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code e…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware CRITICAL 9.8
CVE-2026-20797

A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to cause stack corrup…

Fix: after 1.12.1
Fix from $2,300 2026-02-27
Xweb 300d Pro Firmware CRITICAL 9.1
CVE-2026-22877

An arbitrary file-read vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to read arbitrary files on the…

Fix: after 1.12.1
Fix from $2,300 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-20764

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-23702

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-24452

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execu…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 500b Pro Firmware CRITICAL 9.8
CVE-2026-25085

A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in which an unexpected return value from the authentication routine is later …

Fix: after 1.12.1
Fix from $2,300 2026-02-27
Xweb 500b Pro Firmware HIGH 8.8
CVE-2026-24695

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code ex…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 500b Pro Firmware HIGH 8.8
CVE-2026-25109

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code exec…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 500b Pro Firmware HIGH 8.8
CVE-2026-25111

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware MEDIUM 6.6
CVE-2026-25195

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code exe…

Fix: after 1.12.1
Fix from $1,600 2026-02-27
Xweb 300d Pro Firmware CRITICAL 9.8
CVE-2026-21718

An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to bypass the authentication re…

Fix: after 1.12.1
Fix from $2,300 2026-02-27
Xweb 500b Pro Firmware CRITICAL 9.8
CVE-2026-24663

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code exec…

Fix: after 1.12.1
Fix from $2,300 2026-02-27
Xweb 500b Pro Firmware HIGH 8.8
CVE-2026-24689

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execu…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 500b Pro Firmware HIGH 7.2
CVE-2026-24517

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code exec…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-20742

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execu…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-20902

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code exe…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-20910

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-21389

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
E3 Supervisory Controller Firmware CRITICAL 9.8
CVE-2025-6519

E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably genera…

Fix: 2.31f01+
Fix from $2,300 2025-09-02
E3 Supervisory Controller Firmware CRITICAL 9.8
CVE-2025-52549

E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can generate the root linux passw…

Fix: 2.31f01+
Fix from $2,300 2025-09-02
E3 Supervisory Controller Firmware HIGH 7.5
CVE-2025-52547

E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. An attacker can use this command to con…

Fix: 2.31f01+
Fix from $1,950 2025-09-02
E3 Supervisory Controller Firmware HIGH 7.2
CVE-2025-52550

E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge malicious firmware upgrade pack…

Fix: 2.31f01+
Fix from $1,950 2025-09-02
E3 Supervisory Controller Firmware MEDIUM 6.1
CVE-2025-52546

E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan fil…

Fix: 2.31f01+
Fix from $1,600 2025-09-02
E3 Supervisory Controller Firmware HIGH 7.5
CVE-2025-52543

E3 Site Supervisor Control (firmware version < 2.31F01) application services (MGW and RCI) uses client side hashing for authentication. An attacker c…

Fix: 2.31f01+
Fix from $1,950 2025-09-02
E3 Supervisory Controller Firmware HIGH 7.5
CVE-2025-52544

E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan fil…

Fix: 2.31f01+
Fix from $1,950 2025-09-02