VendorsF5nginx_plusany version
Vulnerabilities

F5 Nginx Plus any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2026-42945
NGINX ngx_http_rewrite_module vulnerability
Published 2026-05-13 · Modified
9.2EPSS 0.034
CVE-2026-9256
NGINX ngx_http_rewrite_module vulnerability
Published 2026-05-22 · Modified
9.2EPSS 0.027
CVE-2026-42055
NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability
Published 2026-06-17 · Modified
9.2EPSS 0.024
CVE-2026-42533
NGINX Map directive and Regex matching vulnerability
Published 2026-07-15 · Analyzed
9.2EPSS 0.009
CVE-2026-60005
NGINX ngx_http_slice_module vulnerability
Published 2026-07-15 · Analyzed
8.8EPSS 0.005
CVE-2026-27651
NGINX ngx_mail_auth_http_module vulnerability
Published 2026-03-24 · Modified
8.7EPSS 0.011
CVE-2026-42946
NGINX ngx_http_scgi_module and ngx_http_uwsgi_module vulnerability
Published 2026-05-13 · Analyzed
8.3EPSS 0.005
CVE-2026-56434
NGINX ngx_http_ssi_module vulnerability
Published 2026-07-15 · Analyzed
8.3EPSS 0.004
CVE-2026-1642
NGINX vulnerability
Published 2026-02-04 · Analyzed
8.2EPSS 0.004
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2022-41743
NGINX ngx_http_hls_module vulnerability CVE-2022-41743
Published 2022-10-19 · Modified
7.0EPSS 0.002
CVE-2026-40460
NGINX ngx_quic_module vulnerability
Published 2026-05-13 · Analyzed
6.9EPSS 0.004
CVE-2026-60065
NGINX Plus ngx_stream_mqtt_filter_module vulnerability
Published 2026-07-15 · Analyzed
6.3EPSS 0.004
CVE-2026-48142
NGINX ngx_http_charset_module vulnerability
Published 2026-06-17 · Analyzed
6.3EPSS 0.004
CVE-2026-42934
NGINX ngx_http_charset_module vulnerability
Published 2026-05-13 · Analyzed
6.3EPSS 0.004
CVE-2026-40701
NGINX ngx_http_ssl_module vulnerability
Published 2026-05-13 · Analyzed
6.3EPSS 0.003
CVE-2024-7347
NGINX MP4 module vulnerability
Published 2024-08-14 · Modified
5.7EPSS 0.003
CVE-2025-23419
TLS Session Resumption Vulnerability
Published 2025-02-05 · Analyzed
5.3EPSS 0.028