58.465 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
F5 vulnerabilities
1039 CVE
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-41373 | CRIT 9.9 | f5 big-ip_access_policy_manager A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful exploit can allow the attacker to cross | 2.4% | — |
| CVE-2021-23031 | CRIT 9.9 | f5 big-ip_advanced_web_application_firewall On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and 11.6.x before 11.6.5.3, an authenticated user may perform a privilege escalation on the BIG-IP Advanced WAF and ASM Configuration u | 2.1% | — |
| CVE-2021-22987 | CRIT 9.9 | f5 big-ip_access_policy_manager On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3 when running in Appliance mode, the Traffic Management User Interface (TMUI), also referred to a | 13.7% | — |
| CVE-2026-94127 | CRIT 9.8 | f5 big-ip_access_policy_manager When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Depl | 2.2% | |
| CVE-2025-53521 | CRIT 9.8 | f5 big-ip_access_policy_manager When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 2.3% | |
| CVE-2023-46747 | CRIT 9.8 | ransomware f5 big-ip_access_policy_manager Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have r | 96.5% | |
| CVE-2022-43286 | CRIT 9.8 | f5 njs Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_json_parse_iterator_call at njs_json.c. | 1.0% | — |
| CVE-2022-29379 | CRIT 9.8 | f5 njs Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/njs_module.c. NOTE: multiple third parties dispute this report, e.g., the behavior is only found in unreleased development code that was not p | 1.8% | — |
| CVE-2022-27007 | CRIT 9.8 | f5 njs nginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a restored frame saved with njs_function_frame_save(). | 1.6% | — |
| CVE-2022-25139 | CRIT 9.8 | f5 njs njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled. | 1.6% | — |
| CVE-2022-1388 | CRIT 9.8 | ransomware f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Softw | 100.0% | |
| CVE-2021-46463 | CRIT 9.8 | f5 njs njs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerability in njs_promise_perform_then(). | 1.7% | — |
| CVE-2021-23008 | CRIT 9.8 | f5 big-ip_access_policy_manager On version 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and all versions of 16.0.x and 11.6.x., BIG-IP APM AD (Active Directory) authentication can be bypassed via a spoofed AS-REP (Kerberos Authentication Service Res | 1.3% | — |
| CVE-2021-22992 | CRIT 9.8 | f5 big-ip_access_policy_manager On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, a malicious HTTP response to an Advanced WAF/BIG-IP ASM virtual server with Login Page configur | 72.7% | — |
| CVE-2021-22991 | CRIT 9.8 | f5 big-ip_access_policy_manager On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI nor | 61.1% | |
| CVE-2021-22986 | CRIT 9.8 | ransomware f5 big-ip_access_policy_manager On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote | 99.9% | |
| CVE-2020-5902 | CRIT 9.8 | ransomware f5 big-ip_access_policy_manager In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclo | 100.0% | |
| CVE-2020-5868 | CRIT 9.8 | f5 big-iq_centralized_management In BIG-IQ 6.0.0-7.0.0, a remote access vulnerability has been discovered that may allow a remote user to execute shell commands on affected systems using HTTP requests to the BIG-IQ user interface. | 2.2% | — |
| CVE-2020-27730 | CRIT 9.8 | f5 nginx_controller In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system utilities. | 1.7% | — |
| CVE-2020-19695 | CRIT 9.8 | f5 njs Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c function. | 1.3% | — |
| CVE-2020-19692 | CRIT 9.8 | f5 njs Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_module.c file. | 1.3% | — |
| CVE-2019-7401 | CRIT 9.8 | f5 nginx_unit NGINX Unit before 1.7.1 might allow an attacker to cause a heap-based buffer overflow in the router process with a specially crafted request. This may result in a denial of service (router process crash) or possibly have unspecified other impact. | 2.9% | — |
| CVE-2019-6675 | CRIT 9.8 | f5 big-ip_access_policy_manager BIG-IP configurations using Active Directory, LDAP, or Client Certificate LDAP for management authentication with multiple servers are exposed to a vulnerability which allows an authentication bypass. This can result in a complete compromise of the system. Thi | 0.9% | — |
| CVE-2019-6609 | CRIT 9.8 | f5 big-ip_access_policy_manager Platform dependent weakness. This issue only impacts iSeries platforms. On these platforms, in BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator) versions 14.0.0-14.1.0.1, 13.0.0-13.1.1.3, and 12.1.1 | 1.5% | — |
| CVE-2019-5021 | CRIT 9.8 | f5 big-ip_controller Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using af | 6.3% | — |