58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
F5 vulnerabilities
1039 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2016-9257 | MED 6.1 | f5 big-ip_access_policy_manager In F5 BIG-IP APM 12.0.0 through 12.1.2, non-authenticated users may be able to inject JavaScript into a request that will then be rendered and executed in the context of the Administrative user when the Administrative user is viewing the Access System Logs, al | 0.8% | — |
| CVE-2018-5538 | LOW 3.7 | f5 big-ip_domain_name_system On F5 BIG-IP DNS 13.1.0-13.1.0.7, 12.1.3-12.1.3.5, DNS Express / DNS Zones accept NOTIFY messages on the management interface from source IP addresses not listed in the 'Allow NOTIFY From' configuration parameter when the db variable "dnsexpress.notifyport" is | 0.8% | — |
| CVE-2022-43285 | HIGH 7.5 | f5 njs Nginx NJS v0.7.4 was discovered to contain a segmentation violation in njs_promise_reaction_job. NOTE: the vendor disputes the significance of this report because NJS does not operate on untrusted input. | 0.8% | — |
| CVE-2022-28859 | MED 6.5 | f5 big-ip_access_policy_manager On F5 BIG-IP 15.1.x versions prior to 15.1.5.1 and 14.1.x versions prior to 14.1.4.6, when installing Net HSM, the scripts (nethsm-safenet-install.sh and nethsm-thales-install.sh) expose the Net HSM partition password. Note: Software versions which have reache | 0.8% | — |
| CVE-2021-23055 | MED 6.5 | f5 nginx_ingress_controller On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not apply to Ingress objects. Note: Software versions which have reached End of Technical Support (EoTS) are not evalua | 0.8% | — |
| CVE-2022-25990 | MED 5.3 | f5 f5os-a On 1.0.x versions prior to 1.0.1, systems running F5OS-A software may expose certain registry ports externally. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0.8% | — |
| CVE-2021-23046 | MED 4.9 | f5 big-ip_access_policy_manager On all versions of Guided Configuration before 8.0.0, when a configuration that contains secure properties is created and deployed from Access Guided Configuration (AGC), secure properties are logged in restnoded logs. Note: Software versions which have reache | 0.8% | — |
| CVE-2020-27726 | MED 6.1 | f5 big-ip_access_policy_manager In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.2, a reflected cross-site scripting (XSS) vulnerability exists in the resource information page for authenticated users when a full webtop is configured on the BIG- | 0.8% | — |
| CVE-2020-27719 | MED 6.1 | f5 big-ip_access_policy_manager On BIG-IP 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, a cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. | 0.8% | — |
| CVE-2020-5927 | MED 6.1 | f5 big-ip_application_security_manager In versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, and 14.1.0-14.1.2.6, BIG-IP ASM Configuration utility Stored-Cross Site Scripting. | 0.8% | — |
| CVE-2025-23239 | HIGH 8.7 | f5 big-ip_access_policy_manager When running in Appliance mode, and logged into a highly-privileged role, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. No | 0.8% | — |
| CVE-2022-35245 | HIGH 7.5 | f5 big-ip_access_policy_manager In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5.1, when a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Softwar | 0.8% | — |
| CVE-2022-35240 | HIGH 7.5 | f5 big-ip_access_policy_manager In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when the Message Routing (MR) Message Queuing Telemetry Transport (MQTT) profile is configured on a virtual server, undisclosed requests can cause an increase in memor | 0.8% | — |
| CVE-2022-35236 | HIGH 7.5 | f5 big-ip_access_policy_manager In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an HTTP2 profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have r | 0.8% | — |
| CVE-2022-34655 | HIGH 7.5 | f5 big-ip_access_policy_manager In BIG-IP Versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an iRule containing the HTTP::payload command is configured on a virtual server, undisclosed traffic can cause Traffic Management Microkernel (TMM) to terminate. | 0.8% | — |
| CVE-2022-34651 | HIGH 7.5 | f5 big-ip_access_policy_manager In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, when an LTM Client or Server SSL profile with TLS 1.3 enabled is configured on a virtual server, along with an iRule that calls HTTP::respond, undisclosed requests can cause the Traffic Mana | 0.8% | — |
| CVE-2022-33203 | HIGH 7.5 | f5 big-ip_access_policy_manager In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when a BIG-IP APM access policy with Service Connect agent is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. | 0.8% | — |
| CVE-2022-28716 | HIGH 7.5 | f5 big-ip_advanced_firewall_manager On 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page o | 0.8% | — |
| CVE-2023-27730 | HIGH 7.5 | f5 njs Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_lvlhsh_find at src/njs_lvlhsh.c. | 0.7% | — |
| CVE-2023-27728 | HIGH 7.5 | f5 njs Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_dump_is_recursive at src/njs_vmcode.c. | 0.7% | — |
| CVE-2022-26415 | HIGH 7.7 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x, when running in Appliance mode, an authenticated user assigned the Administrator | 0.7% | — |
| CVE-2017-0302 | MED 5.3 | f5 big-ip_access_policy_manager In F5 BIG-IP APM 12.0.0 through 12.1.2 and 13.0.0, an authenticated user with an established access session to the BIG-IP APM system may be able to cause a traffic disruption if the length of the requested URL is less than 16 characters. | 0.7% | — |
| CVE-2022-23026 | MED 4.3 | f5 big-ip_advanced_web_application_firewall On BIG-IP ASM & Advanced WAF version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, an authenticated user with low privileges, such as a guest, can upload data using an undisclosed REST endpoint cau | 0.7% | — |
| CVE-2022-35241 | MED 6.5 | f5 nginx_instance_manager In versions 2.x before 2.3.1 and all versions of 1.x, when NGINX Instance Manager is in use, undisclosed requests can cause an increase in disk resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.7% | — |
| CVE-2022-34851 | MED 4.3 | f5 big-ip_access_policy_manager In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ Centralized Management all versions of 8.x, an authenticated attacker may cause iControl SOAP to become un | 0.7% | — |