58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
F5 vulnerabilities
1039 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-25560 | HIGH 7.5 | f5 big-ip_access_policy_manager When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.5% | — |
| CVE-2020-5917 | MED 5.9 | f5 big-ip_access_policy_manager In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2 and BIG-IQ versions 5.2.0-7.0.0, the host OpenSSH servers utilize keys of less than 2048 bits which are no longer considered secure. | 0.5% | — |
| CVE-2020-5870 | HIGH 8.1 | f5 big-iq_centralized_management In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization mechanisms do not use any form of authentication for connecting to the peer. | 0.5% | — |
| CVE-2023-22326 | MED 4.9 | f5 big-ip_access_policy_manager In BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, and all versions of BIG-IQ 8.x and 7.1.x, incorrect permission assignment vulnerabilities exist in the iControl REST | 0.5% | — |
| CVE-2020-5940 | MED 5.4 | f5 big-ip_access_policy_manager In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.2.3, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI), also known as the BIG-IP Configuration utility. | 0.5% | — |
| CVE-2020-5853 | MED 5.4 | f5 big-ip_access_policy_manager In BIG-IP APM portal access on versions 15.0.0-15.1.0, 14.0.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, when backend servers serve HTTP pages with special JavaScript code, this can lead to internal portal access name conflict. | 0.5% | — |
| CVE-2020-5932 | MED 4.8 | f5 big-ip_application_security_manager On BIG-IP ASM 15.1.0-15.1.0.5, a cross-site scripting (XSS) vulnerability exists in the BIG-IP ASM Configuration utility response and blocking pages. An authenticated user with administrative privileges can specify a response page with any content, including J | 0.5% | — |
| CVE-2024-24775 | HIGH 7.5 | f5 big-ip_access_policy_manager When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0.5% | — |
| CVE-2024-23982 | HIGH 7.5 | f5 big-ip_policy_enforcement_manager When a BIG-IP PEM classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This issue affects classification engines using signatures released between 09-08-2022 and | 0.5% | — |
| CVE-2024-23805 | HIGH 7.5 | f5 big-ip_advanced_web_application_firewall Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Application Visibility and Reporting module, this may occur when the HTTP Analytics profile with URLs enabled under Collected Entities is configured on a virtual ser | 0.5% | — |
| CVE-2024-23314 | HIGH 7.5 | f5 big-ip_access_policy_manager When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0.5% | — |
| CVE-2024-23308 | HIGH 7.5 | f5 big-ip_advanced_web_application_firewall When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, undisclosed requests can cause the BD process to terminate. The condition results from setting the Request Body Handling option in the Header- | 0.5% | — |
| CVE-2024-21849 | HIGH 7.5 | f5 big-ip_advanced_web_application_firewall When an Advanced WAF/ASM security policy and a Websockets profile are configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical S | 0.5% | — |
| CVE-2024-21789 | HIGH 7.5 | f5 big-ip_advanced_web_application_firewall When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0.5% | — |
| CVE-2024-21771 | HIGH 7.5 | f5 big-ip_advanced_firewall_manager For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic against signatures, resulting in Traffic Management Microkernel (TMM) restarting and traffic disruption. Note: Software versions which have rea | 0.5% | — |
| CVE-2024-21763 | HIGH 7.5 | f5 big-ip_advanced_firewall_manager When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vector and bad actor detection, undisclosed queries can cause the Traffic Management Microkernel (TMM) to terminate. NOTE: Software versions which have reached End of Technical Supp | 0.5% | — |
| CVE-2023-41085 | HIGH 7.5 | f5 big-ip_access_policy_manager When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.5% | — |
| CVE-2021-22983 | MED 5.4 | f5 big-ip_advanced_firewall_manager On BIG-IP AFM version 15.1.x before 15.1.1, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.5, authenticated users accessing the Configuration utility for AFM are vulnerable to a cross-site scripting attack if they attempt to access a maliciously-crafted URL. | 0.5% | — |
| CVE-2026-55723 | HIGH 8.3 | f5 nginx_ingress_controller When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the gen | 0.5% | — |
| CVE-2022-41780 | MED 5.5 | f5 f5os-a In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.4.0, a directory traversal vulnerability exists in an undisclosed location of the F5OS CLI that allows an attacker to read arbitrary files. | 0.5% | — |
| CVE-2018-5531 | HIGH 7.4 | f5 big-ip_access_policy_manager Through undisclosed methods, on F5 BIG-IP 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.2.1-11.5.6, adjacent network attackers can cause a denial of service for VCMP guest and host systems. Attack must be sourced from adjacent network (layer 2). | 0.5% | — |
| CVE-2022-32455 | HIGH 7.5 | f5 big-ip_access_policy_manager In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when a BIG-IP LTM Client SSL profile is configured on a virtual server to perform client certificate authentication with session tickets enable | 0.5% | — |
| CVE-2026-52865 | MED 6.5 | f5 nginx_ingress_controller When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate. Impact: Th | 0.5% | — |
| CVE-2026-32682 | MED 6.5 | f5 nginx_gateway_fabric When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPCRoute configurations co | 0.5% | — |
| CVE-2020-5913 | HIGH 7.4 | f5 big-ip_access_policy_manager In versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, the BIG-IP Client or Server SSL profile ignores revoked certificates, even when a valid CRL is present. This impacts SSL/TLS connections and may result in a ma | 0.5% | — |