2026 CVE Vulnerabilities

48,537 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-42408MEDIUM6.7When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command that may allow a high...
CVE-2026-42063MEDIUM6.9A vulnerability exists in iControl SOAP where an authenticated attacker with the Resource Administrator or Administrator...
CVE-2026-42058MEDIUM5.3An authenticated attacker's undisclosed requests to BIG-IP iControl REST can lead to an information leak of BIG-IP local...
CVE-2026-41954MEDIUM6.9Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) co...
CVE-2026-40703MEDIUM5.4A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility.  Note: So...
CVE-2026-40701MEDIUM6.3NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client direc...
CVE-2026-40460MEDIUM6.9When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof thei...
CVE-2026-40435MEDIUM6.9When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blo...
CVE-2026-36742MEDIUM6.8Hiseeu C90 v5.7.15 is vulnerable to Insecure Permissions. The UART bootloader is accessible when battery is disconnected...
CVE-2026-36738MEDIUM6.8U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control. The device exposes ...
CVE-2026-34019MEDIUM6.3When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic...
CVE-2026-31156MEDIUM6.5A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program com...
CVE-2026-28758MEDIUM6.7When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return t...
CVE-2026-24464MEDIUM6.9When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that...
CVE-2026-8463MEDIUM5.3Crypt::Argon2 versions from 0.017 before 0.031 for Perl perform a heap out-of-bounds read in argon2_verify on empty enco...
CVE-2026-8369MEDIUM6Improper Input Validation in the NAT64 translator in The OpenThread Authors OpenThread before commit 26a882d on all plat...
CVE-2026-4608MEDIUM6.5The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via th...
CVE-2026-4607MEDIUM4.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in al...
CVE-2026-37429MEDIUM6.5qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysU...
CVE-2026-37428MEDIUM6.5qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysD...
CVE-2026-42961MEDIUM5.1ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF token...
CVE-2026-42950MEDIUM5.1ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a ...
CVE-2026-42948MEDIUM4.8Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrato...
CVE-2026-3426MEDIUM4.3The RTMKit Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing c...
CVE-2026-25107MEDIUM6.9ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now