Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nginx Gateway Fabric HIGH 8.2
CVE-2026-60005

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are co…

Fix: 1.30.4 / 2.6.7+
Fix from $1,950 2026-07-15
Nginx Agent MEDIUM 6.4
CVE-2026-60062

The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secur…

Fix: 2.22.2 / 2.46.7+
Fix from $1,600 2026-07-15
Nginx Gateway Fabric MEDIUM 5.3
CVE-2026-60065

When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated at…

Fix: 2.6.7 / 5.5.3+
Fix from $1,600 2026-07-15
Big Ip Next Cloud Native Network Functions HIGH 7.5
CVE-2026-59762

When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.   Impac…

Fix: 1.4.3 / 1.7.18+
Fix from $1,950 2026-07-15
Nginx Ingress Controller HIGH 8.3
CVE-2026-55723

When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the …

Fix: 5.5.2+
Fix from $1,950 2026-07-15
Nginx Gateway Fabric MEDIUM 6.5
CVE-2026-56434

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (…

Fix: 2.6.7 / 5.5.3+
Fix from $1,600 2026-07-15
Nginx Ingress Controller MEDIUM 6.5
CVE-2026-52865

When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify I…

Fix: 5.5.2+
Fix from $1,600 2026-07-15
Nginx Gateway Fabric HIGH 8.1
CVE-2026-42533

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's rege…

Fix: 2.6.7 / 5.5.3+
Fix from $1,950 2026-07-15
Nginx Gateway Fabric HIGH 8.1
CVE-2026-50107

When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configu…

Fix: 2.6.4+
Fix from $1,950 2026-06-17
Nginx Gateway Fabric MEDIUM 6.5
CVE-2026-32682

When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources c…

Fix: 2.6.4+
Fix from $1,600 2026-06-17
Dos HIGH 8.1
CVE-2026-42055

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists whe…

Fix: 37.0.2.1+
Fix from $1,950 2026-06-17
Nginx Gateway Fabric HIGH 8.1
CVE-2026-42530

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote …

Fix: 1.31.2 / 2.6.4+
Fix from $1,950 2026-06-17
Nginx Gateway Fabric MEDIUM 6.5
CVE-2026-11311

When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator comp…

Fix: 2.6.4+
Fix from $1,600 2026-06-17
Nginx Open Source HIGH 8.1
CVE-2026-9256EPSS 10%

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses …

Fix: 1.30.2 / 2.6.2+
Fix from $1,950 2026-05-22
Njs CRITICAL 9.8
CVE-2026-8711

NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example,…

Fix: 0.9.9+
Fix from $2,300 2026-05-19
Dos HIGH 8.1
CVE-2026-42945EPSS 66%

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is …

Fix: after 5.12.1
Fix from $1,950 2026-05-13
Dos HIGH 7.4
CVE-2026-42946

A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read o…

Fix: after 5.12.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2026-42937

Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and in BIG-IP iControl REST. These…

Fix: after 17.5.1.4
Fix from $1,600 2026-05-13
Big Ip Access Policy Manager HIGH 8.7
CVE-2026-42924

An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager HIGH 8.7
CVE-2026-42930

When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BI…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager HIGH 7.5
CVE-2026-42920

When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic can cause the Traffic Managemen…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager MEDIUM 6.7
CVE-2026-42919

A vulnerability exists in BIG-IP systems that may allow an authenticated attacker with administrative access to escalate their privileges. A successf…

Fix: after 17.5.1
Fix from $1,600 2026-05-13
Nginx Gateway Fabric MEDIUM 5.8
CVE-2026-42926

When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be abl…

Fix: after 5.4.2
Fix from $1,600 2026-05-13
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2026-42781

When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cause an increase in ePVA and Tr…

Fix: after 17.5.1
Fix from $1,600 2026-05-13
Big Ip Access Policy Manager HIGH 8.7
CVE-2026-42406

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can …

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Next Cloud Native Network Functions HIGH 7.5
CVE-2026-42409

When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a virtual server, undisclosed requests c…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2026-41959

Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and in BIG-IP iControl REST…

Fix: after 17.5.1
Fix from $1,600 2026-05-13
Big Ip Access Policy Manager HIGH 8.8
CVE-2026-41957

An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility.  Note: Softw…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager HIGH 8.7
CVE-2026-41953

A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify c…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager HIGH 7.5
CVE-2026-41956

When a classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to termi…

Fix: after 17.5.1
Fix from $1,950 2026-05-13