2026 CVE Vulnerabilities

50,998 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-40060HIGH8.7When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the ...
CVE-2026-39459HIGH8.6A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with...
CVE-2026-39458HIGH7.5When a BIG-IP is configured with DNS caching (Such as a DNS profile with caching enabled, SSL Orchestrator, Advanced WA...
CVE-2026-39455HIGH8.7When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, ...
CVE-2026-36741HIGH7.2U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Command Injection. The Network Time Protocol ...
CVE-2026-35062HIGH7.1An authenticated iControl SOAP user may be able to obtain information of other accounts.  Note: Software versions which...
CVE-2026-34176HIGH8.7When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iContro...
CVE-2026-32673HIGH8.7A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administra...
CVE-2026-32643HIGH8.7A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the ...
CVE-2026-20916HIGH8.1An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iCon...
CVE-2026-4609HIGH7.1The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to...
CVE-2026-39806HIGH7.5Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remote den...
CVE-2026-39803HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denia...
CVE-2026-37430HIGH7.3An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a allow...
CVE-2026-6177HIGH7.2The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and includi...
CVE-2026-3425HIGH8.8The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in...
CVE-2026-35506HIGH8.6ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr par...
CVE-2026-6276HIGH7.5Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done u...
CVE-2026-5773HIGH7.5libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent ...
CVE-2026-4798HIGH7.5The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in al...
CVE-2026-25710HIGH7The new upstream added a privileged D-Bus helper called plasmaloginauthhelper, which suffers from multiple issues, e.g.a...
CVE-2026-25705HIGH8.4A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-ra...
CVE-2026-6929HIGH7.5The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based blin...
CVE-2026-44612HIGH8.4Bytello Share (Windows Edition) installer executable provided by Bytello insecurely loads Dynamic Link Libraries. If the...
CVE-2026-21020HIGH7.8Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to tri...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now