IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

F5 vulnerabilities

1039 CVE

F5 vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-41164 MED 5.9 f5 big-ip_access_policy_manager When TCP profile with Multipath TCP enabled (MPTCP) is configured on a Virtual Server, undisclosed traffic along with conditions beyond the attackers control can cause TMM to terminate. Note: Software versions which have reached End of Technical Support ( 0.4% —
CVE-2024-39809 HIGH 7.5 f5 big-ip_next_central_manager The Central Manager user session refresh token does not expire when a user logs out.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated 0.4% —
CVE-2025-24320 HIGH 8.0 f5 big-ip_access_policy_manager A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. This vulnerability is due to an incomplete fix for CV 0.4% —
CVE-2023-43746 HIGH 8.7 f5 big-ip_access_policy_manager When running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing BIG-IP external monitor on a BIG-IP system.  A successful exploit can allow the attacker to cross a security bou 0.4% —
CVE-2025-14727 HIGH 8.3 f5 nginx_ingress_controller A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.4% —
CVE-2022-34865 MED 4.8 f5 big-ip_access_policy_manager In BIG-IP Versions 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, Traffic Intelligence feeds, which use HTTPS, do not verify the remote endpoint identity, allowing for potential data poisoning. Note: Software versions which have reac 0.4% —
CVE-2025-46706 HIGH 7.5 f5 big-ip_access_policy_manager When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.4% —
CVE-2025-36546 HIGH 8.1 f5 f5os-a On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication, and then enabled Appliance Mode; access via SSH key-based authentication is still allowed. For an attacker to exploit this vulnerability t 0.4% —
CVE-2026-56434 MED 6.5 f5 nginx_gateway_fabric NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticate 0.4% —
CVE-2026-42919 MED 6.7 f5 big-ip_access_policy_manager A vulnerability exists in BIG-IP systems that may allow an authenticated attacker with administrative access to escalate their privileges. A successful exploit may allow the attacker to cross a security boundary.  Note: Software versions which have reached En 0.4% —
CVE-2025-41433 HIGH 7.5 f5 big-ip_access_policy_manager When a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured on a Message Routing virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: 0.4% —
CVE-2025-41431 HIGH 7.5 f5 big-ip_access_policy_manager When connection mirroring is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate in the standby BIG-IP systems in a traffic group. Note: Software versions which have reached End of Technical S 0.4% —
CVE-2025-36525 HIGH 7.5 f5 big-ip_access_policy_manager When a BIG-IP APM virtual server is configured to use a PingAccess profile, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.4% —
CVE-2025-36504 HIGH 7.5 f5 big-ip_access_policy_manager When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.4% —
CVE-2025-35995 HIGH 7.5 f5 big-ip_policy_enforcement_manager When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or an iRule with the urlcat command is enabled on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Soft 0.4% —
CVE-2017-6143 MED 5.4 f5 big-ip_advanced_firewall_manager X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the remote server's identity is not properly validated in F5 BIG-IP 12.0.0-12.1.2, 11.6.0-11.6.2, or 11.5.0-11.5.5. 0.4% —
CVE-2020-24348 MED 5.5 f5 njs njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_json_stringify_iterator in njs_json.c. 0.4% —
CVE-2020-24347 MED 5.5 f5 njs njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_lvlhsh_level_find in njs_lvlhsh.c. 0.4% —
CVE-2025-53859 LOW 3.7 f5 nginx_open_source NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP authentication process memory; as a result, the server side may leak arbitrary bytes sent in a request to the 0.4% —
CVE-2025-41414 HIGH 7.5 f5 big-ip_access_policy_manager When HTTP/2 client and server profile is configured on a virtual server, undisclosed requests can cause TMM to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated 0.4% —
CVE-2025-41399 HIGH 7.5 f5 big-ip_access_policy_manager When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluate 0.4% —
CVE-2025-36557 HIGH 7.5 f5 big-ip_access_policy_manager When an HTTP profile with the Enforce RFC Compliance option is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are 0.4% —
CVE-2018-5518 MED 5.4 f5 big-ip_access_policy_manager On F5 BIG-IP 13.0.0-13.1.0.5 or 12.0.0-12.1.3.3, malicious root users with access to a VCMP guest can cause a disruption of service on adjacent VCMP guests running on the same host. Exploiting this vulnerability causes the vCMPd process on the adjacent VCMP gu 0.4% —
CVE-2025-22891 HIGH 7.5 f5 big-ip_policy_enforcement_manager When BIG-IP PEM Control Plane listener Virtual Server is configured with Diameter Endpoint profile, undisclosed traffic can cause the Virtual Server to stop processing new client connections and an increase in memory resource utilization. Note: Software versio 0.4% —
CVE-2018-5540 MED 4.4 f5 big-ip_domain_name_system On F5 BIG-IP 13.0.0-13.0.1, 12.1.0-12.1.3.3, 11.6.0-11.6.3.1, or 11.5.1-11.5.6, Enterprise Manager 3.1.1, BIG-IQ Centralized Management 5.0.0-5.1.0, BIG-IQ Cloud and Orchestration 1.0.0, or F5 iWorkflow 2.1.0-2.3.0 the big3d process does not irrevocably minimi 0.4% —