Every CVE whose affected-product data names F5 Waf, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (12)
CVE-2026-60005 — CVSS 8.2 (high): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex…
CVE-2026-42945 — CVSS 8.1 (high): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite…
CVE-2026-9256 — CVSS 8.1 (high): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite…
CVE-2026-42055 — CVSS 8.1 (high): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability…
CVE-2026-42533 — CVSS 8.1 (high): A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the…
CVE-2026-42946 — CVSS 6.5 (medium): A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an…
CVE-2026-40460 — CVSS 6.5 (medium): When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address…
CVE-2026-56434 — CVSS 6.5 (medium): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side…
CVE-2026-40701 — CVSS 4.8 (medium): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on"…
CVE-2026-42934 — CVSS 4.8 (medium): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map…
CVE-2026-48142 — CVSS 4.8 (medium): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a…
CVE-2026-60065 — CVSS 3.7 (low): When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module)…