Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.2 CVE-2026-60005 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are co… Nginx Gateway Fabric 1.30.4 / 2.6.7+ Fix from $1,9502026-07-15 MEDIUM 6.4 CVE-2026-60062 The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secur… Nginx Agent 2.22.2 / 2.46.7+ Fix from $1,6002026-07-15 MEDIUM 5.3 CVE-2026-60065 When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated at… Nginx Gateway Fabric 2.6.7 / 5.5.3+ Fix from $1,6002026-07-15 HIGH 7.5 CVE-2026-59762 When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.   Impac… Big Ip Next Cloud Native Network Functions 1.4.3 / 1.7.18+ Fix from $1,9502026-07-15 HIGH 8.3 CVE-2026-55723 When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the … Nginx Ingress Controller 5.5.2+ Fix from $1,9502026-07-15 MEDIUM 6.5 CVE-2026-56434 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (… Nginx Gateway Fabric 2.6.7 / 5.5.3+ Fix from $1,6002026-07-15 MEDIUM 6.5 CVE-2026-52865 When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify I… Nginx Ingress Controller 5.5.2+ Fix from $1,6002026-07-15 HIGH 8.1 CVE-2026-42533 A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's rege… Nginx Gateway Fabric 2.6.7 / 5.5.3+ Fix from $1,9502026-07-15 HIGH 8.1 CVE-2026-50107 When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configu… Nginx Gateway Fabric 2.6.4+ Fix from $1,9502026-06-17 MEDIUM 6.5 CVE-2026-32682 When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources c… Nginx Gateway Fabric 2.6.4+ Fix from $1,6002026-06-17 HIGH 8.1 CVE-2026-42055 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists whe… Dos 37.0.2.1+ Fix from $1,9502026-06-17 HIGH 8.1 CVE-2026-42530 NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote … Nginx Gateway Fabric 1.31.2 / 2.6.4+ Fix from $1,9502026-06-17 MEDIUM 6.5 CVE-2026-11311 When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator comp… Nginx Gateway Fabric 2.6.4+ Fix from $1,6002026-06-17 HIGH 8.1 CVE-2026-9256EPSS 10% NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses … Nginx Open Source 1.30.2 / 2.6.2+ Fix from $1,9502026-05-22 CRITICAL 9.8 CVE-2026-8711 NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example,… Njs 0.9.9+ Fix from $2,3002026-05-19 HIGH 8.1 CVE-2026-42945EPSS 66% NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is … Dos after 5.12.1 Fix from $1,9502026-05-13 HIGH 7.4 CVE-2026-42946 A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read o… Dos after 5.12.1 Fix from $1,9502026-05-13 MEDIUM 6.5 CVE-2026-42937 Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and in BIG-IP iControl REST. These… Big Ip Access Policy Manager after 17.5.1.4 Fix from $1,6002026-05-13 HIGH 8.7 CVE-2026-42924 An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 HIGH 8.7 CVE-2026-42930 When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BI… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-42920 When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic can cause the Traffic Managemen… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 MEDIUM 6.7 CVE-2026-42919 A vulnerability exists in BIG-IP systems that may allow an authenticated attacker with administrative access to escalate their privileges. A successf… Big Ip Access Policy Manager after 17.5.1 Fix from $1,6002026-05-13 MEDIUM 5.8 CVE-2026-42926 When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be abl… Nginx Gateway Fabric after 5.4.2 Fix from $1,6002026-05-13 MEDIUM 6.5 CVE-2026-42781 When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cause an increase in ePVA and Tr… Big Ip Access Policy Manager after 17.5.1 Fix from $1,6002026-05-13 HIGH 8.7 CVE-2026-42406 A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can … Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-42409 When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a virtual server, undisclosed requests c… Big Ip Next Cloud Native Network Functions after 17.5.1 Fix from $1,9502026-05-13 MEDIUM 6.5 CVE-2026-41959 Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and in BIG-IP iControl REST… Big Ip Access Policy Manager after 17.5.1 Fix from $1,6002026-05-13 HIGH 8.8 CVE-2026-41957 An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility.  Note: Softw… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 HIGH 8.7 CVE-2026-41953 A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify c… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-41956 When a classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to termi… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13