CVE Vulnerability Database

Search and browse 397,994 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-40629HIGH8.7When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processin...
CVE-2026-40618HIGH8.7When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technolog...
CVE-2026-40462HIGH7.1Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command which m...
CVE-2026-40460MEDIUM6.9When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof thei...
CVE-2026-40435MEDIUM6.9When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blo...
CVE-2026-40423HIGH8.7When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (...
CVE-2026-40067HIGH8.7When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to ter...
CVE-2026-40061HIGH8.7When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) comm...
CVE-2026-40060HIGH8.7When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the ...
CVE-2026-39459HIGH8.6A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with...
CVE-2026-39458HIGH7.5When a BIG-IP is configured with DNS caching (Such as a DNS profile with caching enabled, SSL Orchestrator, Advanced WA...
CVE-2026-39455HIGH8.7When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, ...
CVE-2026-36742MEDIUM6.8Hiseeu C90 v5.7.15 is vulnerable to Insecure Permissions. The UART bootloader is accessible when battery is disconnected...
CVE-2026-36741HIGH7.2U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Command Injection. The Network Time Protocol ...
CVE-2026-36738MEDIUM6.8U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control. The device exposes ...
CVE-2026-35062HIGH7.1An authenticated iControl SOAP user may be able to obtain information of other accounts.  Note: Software versions which...
CVE-2026-34176HIGH8.7When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iContro...
CVE-2026-34019MEDIUM6.3When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic...
CVE-2026-32673HIGH8.7A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administra...
CVE-2026-32643HIGH8.7A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the ...
CVE-2026-31156MEDIUM6.5A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program com...
CVE-2026-28758MEDIUM6.7When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return t...
CVE-2026-24464MEDIUM6.9When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that...
CVE-2026-20916HIGH8.1An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iCon...
CVE-2025-32425MEDIUM5.5AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut...