Aggregator
CVE-2026-42945 | F5 NGINX Plus/NGINX Open Source HTTP ngx_http_rewrite_module heap-based overflow (K000161019)
20 minutes 39 seconds ago
A vulnerability has been found in F5 NGINX Plus and NGINX Open Source and classified as critical. This affects the function ngx_http_rewrite_module of the component HTTP Handler. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2026-42945. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-42920 | F5 BIG-IP prior 17.1.3.1/17.5.1.4/21.0.0.1 Traffic Management Microkernel infinite loop (K000160901)
20 minutes 49 seconds ago
A vulnerability, which was classified as problematic, was found in F5 BIG-IP. The impacted element is an unknown function of the component Traffic Management Microkernel. Executing a manipulation can lead to infinite loop.
This vulnerability appears as CVE-2026-42920. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2026-42557 | Jupyter notebook up to 4.5.6 cross site scripting
21 minutes 1 second ago
A vulnerability, which was classified as problematic, has been found in Jupyter notebook up to 4.5.6. The affected element is an unknown function. Performing a manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-42557. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-42409 | F5 BIG-IP Traffic Management Microkernel respond null pointer dereference (K000159034)
21 minutes 20 seconds ago
A vulnerability classified as problematic was found in F5 BIG-IP, BIG-IP Next SPK, BIG-IP Next CNF and BIG-IP Next for Kubernetes. Impacted is the function HTTP::redirect/HTTP::respond of the component Traffic Management Microkernel. Such manipulation leads to null pointer dereference.
This vulnerability is documented as CVE-2026-42409. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-41956 | F5 BIG-IP/BIG-IP Next CNF/BIG-IP Next for Kubernetes Traffic Management Microkernel stack-based overflow (K000158038)
21 minutes 38 seconds ago
A vulnerability classified as critical has been found in F5 BIG-IP, BIG-IP Next CNF and BIG-IP Next for Kubernetes. This issue affects some unknown processing of the component Traffic Management Microkernel. This manipulation causes stack-based buffer overflow.
This vulnerability is registered as CVE-2026-41956. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-41954 | F5 BIG-IP/BIG-IQ iControl REST Endpoint information disclosure (K32950402)
21 minutes 50 seconds ago
A vulnerability described as problematic has been identified in F5 BIG-IP and BIG-IQ. This vulnerability affects unknown code of the component iControl REST Endpoint. The manipulation results in information disclosure.
This vulnerability is cataloged as CVE-2026-41954. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-41227 | F5 BIG-IP prior 17.1.3.1/17.5.1.4 allocation of resources (K000158979)
22 minutes 10 seconds ago
A vulnerability marked as critical has been reported in F5 BIG-IP. This affects an unknown part. The manipulation leads to allocation of resources.
This vulnerability is listed as CVE-2026-41227. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-41218 | F5 BIG-IP prior 17.1.3.1/17.5.1.4/21.0.0.1 Traffic Management Microkernel use after free (K000160875)
22 minutes 18 seconds ago
A vulnerability labeled as critical has been found in F5 BIG-IP. Affected by this issue is some unknown functionality of the component Traffic Management Microkernel. Executing a manipulation can lead to use after free.
This vulnerability is tracked as CVE-2026-41218. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-41217 | F5 BIG-IP prior 17.1.3.2/17.5.1.6/21.0.0.2 TMOS Shell permission assignment (K000161107)
22 minutes 20 seconds ago
A vulnerability identified as problematic has been detected in F5 BIG-IP. Affected by this vulnerability is an unknown functionality of the component TMOS Shell. Performing a manipulation results in incorrect permission assignment.
This vulnerability is identified as CVE-2026-41217. The attack is only possible with local access. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-40701 | F5 NGINX Plus/NGINX Open Source Configuration ngx_http_ssl_module use after free (K000161021)
22 minutes 23 seconds ago
A vulnerability categorized as critical has been discovered in F5 NGINX Plus and NGINX Open Source. Affected is the function ngx_http_ssl_module of the component Configuration Handler. Such manipulation leads to use after free.
This vulnerability is referenced as CVE-2026-40701. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-40618 | F5 BIG-IP prior 17.1.3.1/17.1.5.4/21.0.0.1 Traffic Management Microkernel buffer size (K000158082)
23 minutes 46 seconds ago
A vulnerability was found in F5 BIG-IP, BIG-IP Next SPK, BIG-IP Next CNF and BIG-IP Next for Kubernetes. It has been rated as critical. This impacts an unknown function of the component Traffic Management Microkernel. This manipulation causes incorrect calculation of buffer size.
The identification of this vulnerability is CVE-2026-40618. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-40460 | F5 NGINX Plus/NGINX Open Source Source IP Address authentication spoofing (K000161068)
23 minutes 49 seconds ago
A vulnerability was found in F5 NGINX Plus and NGINX Open Source. It has been declared as critical. This affects an unknown function of the component Source IP Address Handler. The manipulation results in authentication bypass by spoofing.
This vulnerability was named CVE-2026-40460. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-40061 | F5 BIG-IP prior 17.1.3.1/17.5.1.4/21.0.0.1 iControl REST command injection (K000160788)
24 minutes ago
A vulnerability was found in F5 BIG-IP. It has been classified as critical. The impacted element is an unknown function of the component iControl REST Handler. The manipulation leads to command injection.
This vulnerability is uniquely identified as CVE-2026-40061. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-40423 | F5 BIG-IP prior 17.1.3.2/17.5.1.6/21.0.0.2 Traffic Management Microkernel allocation of resources (K000161023)
24 minutes 2 seconds ago
A vulnerability was found in F5 BIG-IP and classified as critical. The affected element is an unknown function of the component Traffic Management Microkernel. Executing a manipulation can lead to allocation of resources.
This vulnerability is handled as CVE-2026-40423. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-39458 | F5 BIG-IP prior 17.1.3.2/17.5.1.6/21.0.0.1 Traffic Management Microkernel uninitialized pointer (K000160945)
24 minutes 5 seconds ago
A vulnerability has been found in F5 BIG-IP and classified as critical. Impacted is an unknown function of the component Traffic Management Microkernel. Performing a manipulation results in uninitialized pointer.
This vulnerability is known as CVE-2026-39458. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2026-34176 | F5 BIG-IP prior 17.1.3.2/17.5.1.6/21.0.0.2 iControl REST Endpoint os command injection (K000160857)
24 minutes 7 seconds ago
A vulnerability, which was classified as critical, was found in F5 BIG-IP. This issue affects some unknown processing of the component iControl REST Endpoint. Such manipulation leads to os command injection.
This vulnerability is traded as CVE-2026-34176. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-34019 | F5 BIG-IP up to 17.1.2/17.5.0 Traffic Management Microkernel resource pool (K000150508)
24 minutes 9 seconds ago
A vulnerability, which was classified as problematic, has been found in F5 BIG-IP up to 17.1.2/17.5.0. This vulnerability affects unknown code of the component Traffic Management Microkernel. This manipulation causes insufficient resource pool.
This vulnerability appears as CVE-2026-34019. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2020-37219 | Fabrikar com_fabrik 3.9.11 onAjax_files folder path traversal (Exploit 48263)
24 minutes 18 seconds ago
A vulnerability classified as critical was found in Fabrikar com_fabrik 3.9.11. This affects the function onAjax_files. The manipulation of the argument folder results in path traversal.
This vulnerability is reported as CVE-2020-37219. The attack can be launched remotely. Moreover, an exploit is present.
vuldb.com
CVE-2020-37168 | Paiement Ecommerce Systempay 1.0 Payment Endpoint weak hash (Exploit 48017)
24 minutes 29 seconds ago
A vulnerability classified as critical has been found in Paiement Ecommerce Systempay 1.0. Affected by this issue is some unknown functionality of the component Payment Endpoint. The manipulation leads to use of weak hash.
This vulnerability is documented as CVE-2020-37168. The attack can be initiated remotely. Additionally, an exploit exists.
vuldb.com