2026 CVE Vulnerabilities
50,998 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40060 | HIGH | 8.7 | 0.3% | May 13, 2026 | When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the ... |
| CVE-2026-39459 | HIGH | 8.6 | 0.3% | May 13, 2026 | A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with... |
| CVE-2026-39458 | HIGH | 7.5 | 0.3% | May 13, 2026 | When a BIG-IP is configured with DNS caching (Such as a DNS profile with caching enabled, SSL Orchestrator, Advanced WA... |
| CVE-2026-39455 | HIGH | 8.7 | 0.3% | May 13, 2026 | When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, ... |
| CVE-2026-36741 | HIGH | 7.2 | 1.1% | May 13, 2026 | U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Command Injection. The Network Time Protocol ... |
| CVE-2026-35062 | HIGH | 7.1 | 0.2% | May 13, 2026 | An authenticated iControl SOAP user may be able to obtain information of other accounts. Note: Software versions which... |
| CVE-2026-34176 | HIGH | 8.7 | 0.7% | May 13, 2026 | When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iContro... |
| CVE-2026-32673 | HIGH | 8.7 | 0.2% | May 13, 2026 | A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administra... |
| CVE-2026-32643 | HIGH | 8.7 | 0.2% | May 13, 2026 | A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the ... |
| CVE-2026-20916 | HIGH | 8.1 | 0.4% | May 13, 2026 | An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iCon... |
| CVE-2026-4609 | HIGH | 7.1 | 0.2% | May 13, 2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to... |
| CVE-2026-39806 | HIGH | 7.5 | 0.6% | May 13, 2026 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remote den... |
| CVE-2026-39803 | HIGH | 7.5 | 0.6% | May 13, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denia... |
| CVE-2026-37430 | HIGH | 7.3 | 0.3% | May 13, 2026 | An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a allow... |
| CVE-2026-6177 | HIGH | 7.2 | 0.5% | May 13, 2026 | The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and includi... |
| CVE-2026-3425 | HIGH | 8.8 | 0.6% | May 13, 2026 | The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in... |
| CVE-2026-35506 | HIGH | 8.6 | 1.3% | May 13, 2026 | ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr par... |
| CVE-2026-6276 | HIGH | 7.5 | 0.3% | May 13, 2026 | Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done u... |
| CVE-2026-5773 | HIGH | 7.5 | 0.5% | May 13, 2026 | libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent ... |
| CVE-2026-4798 | HIGH | 7.5 | 0.5% | May 13, 2026 | The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in al... |
| CVE-2026-25710 | HIGH | 7 | 0.1% | May 13, 2026 | The new upstream added a privileged D-Bus helper called plasmaloginauthhelper, which suffers from multiple issues, e.g.a... |
| CVE-2026-25705 | HIGH | 8.4 | 0.4% | May 13, 2026 | A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-ra... |
| CVE-2026-6929 | HIGH | 7.5 | 0.3% | May 13, 2026 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based blin... |
| CVE-2026-44612 | HIGH | 8.4 | 0.1% | May 13, 2026 | Bytello Share (Windows Edition) installer executable provided by Bytello insecurely loads Dynamic Link Libraries. If the... |
| CVE-2026-21020 | HIGH | 7.8 | 0.1% | May 13, 2026 | Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to tri... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now