2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32673 | HIGH | 8.7 | 0.2% | May 13, 2026 | A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administra... |
| CVE-2026-32643 | HIGH | 8.7 | 0.2% | May 13, 2026 | A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the ... |
| CVE-2026-31156 | MEDIUM | 6.5 | 0.4% | May 13, 2026 | A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program com... |
| CVE-2026-28758 | MEDIUM | 6.7 | 0.1% | May 13, 2026 | When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return t... |
| CVE-2026-24464 | MEDIUM | 6.9 | 0.9% | May 13, 2026 | When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that... |
| CVE-2026-20916 | HIGH | 8.1 | 0.4% | May 13, 2026 | An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iCon... |
| CVE-2026-8463 | MEDIUM | 5.3 | 0.3% | May 13, 2026 | Crypt::Argon2 versions from 0.017 before 0.031 for Perl perform a heap out-of-bounds read in argon2_verify on empty enco... |
| CVE-2026-8369 | MEDIUM | 6 | 0.2% | May 13, 2026 | Improper Input Validation in the NAT64 translator in The OpenThread Authors OpenThread before commit 26a882d on all plat... |
| CVE-2026-4609 | HIGH | 7.1 | 0.2% | May 13, 2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to... |
| CVE-2026-4608 | MEDIUM | 6.5 | 0.3% | May 13, 2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via th... |
| CVE-2026-4607 | MEDIUM | 4.3 | 0.2% | May 13, 2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in al... |
| CVE-2026-39806 | HIGH | 7.5 | 0.6% | May 13, 2026 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remote den... |
| CVE-2026-39803 | HIGH | 7.5 | 0.6% | May 13, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denia... |
| CVE-2026-37430 | HIGH | 7.3 | 0.3% | May 13, 2026 | An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a allow... |
| CVE-2026-37429 | MEDIUM | 6.5 | 0.3% | May 13, 2026 | qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysU... |
| CVE-2026-37428 | MEDIUM | 6.5 | 0.2% | May 13, 2026 | qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysD... |
| CVE-2026-6177 | HIGH | 7.2 | 0.5% | May 13, 2026 | The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and includi... |
| CVE-2026-42961 | MEDIUM | 5.1 | 0.2% | May 13, 2026 | ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF token... |
| CVE-2026-42950 | MEDIUM | 5.1 | 0.2% | May 13, 2026 | ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a ... |
| CVE-2026-42948 | MEDIUM | 4.8 | 0.2% | May 13, 2026 | Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrato... |
| CVE-2026-42062 | CRITICAL | 9.8 | 1.6% | May 13, 2026 | ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If process... |
| CVE-2026-40621 | CRITICAL | 9.8 | 0.5% | May 13, 2026 | ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected produc... |
| CVE-2026-3426 | MEDIUM | 4.3 | 0.3% | May 13, 2026 | The RTMKit Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing c... |
| CVE-2026-3425 | HIGH | 8.8 | 0.6% | May 13, 2026 | The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in... |
| CVE-2026-35506 | HIGH | 8.6 | 1.3% | May 13, 2026 | ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr par... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now