Skip to main content

Vendor archive

f5 CVEs

Beta · best-effort

1,024 CVEs tagged to vendor f575 Critical, 562 High, 372 Medium, 15 Low, 0 Unrated.

CVE-2026-28758

Published May 13, 2026

When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return the ssh-password parameter in cleartext in the iControl REST…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-20916

Published May 13, 2026

An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system.  Note: Software ve…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-32647

Published Mar 24, 2026

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX wor…

CVSS 8.5 · High
evidence mentions
19
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2026-28755

Published Mar 24, 2026

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-28753

Published Mar 24, 2026

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-c…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-27784

Published Mar 24, 2026

The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory…

CVSS 8.5 · High
evidence mentions
19
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2026-27654

Published Mar 24, 2026

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this…

CVSS 8.8 · High
evidence mentions
19
Buzz score
48.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-27651

Published Mar 24, 2026

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1…

CVSS 8.7 · High
evidence mentions
19
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2025-14727

Published Dec 17, 2025

A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software versions which have reached End of Technical Support (EoTS)…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 51-75 of 1,024 CVEsPage 3 of 41