2026 CVE Vulnerabilities
48,537 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42408 | MEDIUM | 6.7 | 0.1% | May 13, 2026 | When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command that may allow a high... |
| CVE-2026-42063 | MEDIUM | 6.9 | 0.3% | May 13, 2026 | A vulnerability exists in iControl SOAP where an authenticated attacker with the Resource Administrator or Administrator... |
| CVE-2026-42058 | MEDIUM | 5.3 | 0.2% | May 13, 2026 | An authenticated attacker's undisclosed requests to BIG-IP iControl REST can lead to an information leak of BIG-IP local... |
| CVE-2026-41954 | MEDIUM | 6.9 | 0.3% | May 13, 2026 | Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) co... |
| CVE-2026-40703 | MEDIUM | 5.4 | 0.1% | May 13, 2026 | A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility. Note: So... |
| CVE-2026-40701 | MEDIUM | 6.3 | 0.7% | May 13, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client direc... |
| CVE-2026-40460 | MEDIUM | 6.9 | 0.4% | May 13, 2026 | When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof thei... |
| CVE-2026-40435 | MEDIUM | 6.9 | 0.2% | May 13, 2026 | When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blo... |
| CVE-2026-36742 | MEDIUM | 6.8 | 0.2% | May 13, 2026 | Hiseeu C90 v5.7.15 is vulnerable to Insecure Permissions. The UART bootloader is accessible when battery is disconnected... |
| CVE-2026-36738 | MEDIUM | 6.8 | 0.2% | May 13, 2026 | U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control. The device exposes ... |
| CVE-2026-34019 | MEDIUM | 6.3 | 0.3% | May 13, 2026 | When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic... |
| CVE-2026-31156 | MEDIUM | 6.5 | 0.4% | May 13, 2026 | A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program com... |
| CVE-2026-28758 | MEDIUM | 6.7 | 0.1% | May 13, 2026 | When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return t... |
| CVE-2026-24464 | MEDIUM | 6.9 | 0.9% | May 13, 2026 | When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that... |
| CVE-2026-8463 | MEDIUM | 5.3 | 0.3% | May 13, 2026 | Crypt::Argon2 versions from 0.017 before 0.031 for Perl perform a heap out-of-bounds read in argon2_verify on empty enco... |
| CVE-2026-8369 | MEDIUM | 6 | 0.2% | May 13, 2026 | Improper Input Validation in the NAT64 translator in The OpenThread Authors OpenThread before commit 26a882d on all plat... |
| CVE-2026-4608 | MEDIUM | 6.5 | 0.3% | May 13, 2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via th... |
| CVE-2026-4607 | MEDIUM | 4.3 | 0.2% | May 13, 2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in al... |
| CVE-2026-37429 | MEDIUM | 6.5 | 0.3% | May 13, 2026 | qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysU... |
| CVE-2026-37428 | MEDIUM | 6.5 | 0.2% | May 13, 2026 | qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysD... |
| CVE-2026-42961 | MEDIUM | 5.1 | 0.2% | May 13, 2026 | ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF token... |
| CVE-2026-42950 | MEDIUM | 5.1 | 0.2% | May 13, 2026 | ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a ... |
| CVE-2026-42948 | MEDIUM | 4.8 | 0.2% | May 13, 2026 | Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrato... |
| CVE-2026-3426 | MEDIUM | 4.3 | 0.3% | May 13, 2026 | The RTMKit Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing c... |
| CVE-2026-25107 | MEDIUM | 6.9 | 0.1% | May 13, 2026 | ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now