2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32673HIGH8.7A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administra...
CVE-2026-32643HIGH8.7A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the ...
CVE-2026-31156MEDIUM6.5A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program com...
CVE-2026-28758MEDIUM6.7When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return t...
CVE-2026-24464MEDIUM6.9When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that...
CVE-2026-20916HIGH8.1An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iCon...
CVE-2026-8463MEDIUM5.3Crypt::Argon2 versions from 0.017 before 0.031 for Perl perform a heap out-of-bounds read in argon2_verify on empty enco...
CVE-2026-8369MEDIUM6Improper Input Validation in the NAT64 translator in The OpenThread Authors OpenThread before commit 26a882d on all plat...
CVE-2026-4609HIGH7.1The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to...
CVE-2026-4608MEDIUM6.5The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via th...
CVE-2026-4607MEDIUM4.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in al...
CVE-2026-39806HIGH7.5Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remote den...
CVE-2026-39803HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denia...
CVE-2026-37430HIGH7.3An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a allow...
CVE-2026-37429MEDIUM6.5qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysU...
CVE-2026-37428MEDIUM6.5qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysD...
CVE-2026-6177HIGH7.2The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and includi...
CVE-2026-42961MEDIUM5.1ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF token...
CVE-2026-42950MEDIUM5.1ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a ...
CVE-2026-42948MEDIUM4.8Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrato...
CVE-2026-42062CRITICAL9.8ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If process...
CVE-2026-40621CRITICAL9.8ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected produc...
CVE-2026-3426MEDIUM4.3The RTMKit Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing c...
CVE-2026-3425HIGH8.8The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in...
CVE-2026-35506HIGH8.6ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr par...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now