58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
Vulnerabilità F5
1039 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-1642 | MED 5.9 | f5 nginx_gateway_fabric A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control | 0,4% | — |
| CVE-2013-6024 | MED 4.4 | f5 big-ip_access_policy_manager The Edge Client components in F5 BIG-IP APM 10.x, 11.x, 12.x, 13.x, and 14.x, BIG-IP Edge Gateway 10.x and 11.x, and FirePass 7.0.0 allow attackers to obtain sensitive information from process memory via unspecified vectors. | 0,4% | — |
| CVE-2025-61990 | HIGH 7.5 | f5 big-ip_access_policy_manager When using a multi-bladed platform with more than one blade, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,3% | — |
| CVE-2025-61935 | HIGH 7.5 | f5 big-ip_advanced_web_application_firewall When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,3% | — |
| CVE-2025-61960 | HIGH 7.5 | f5 big-ip_access_policy_manager When a per-request policy is configured on a BIG-IP APM portal access virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evalu | 0,3% | — |
| CVE-2025-61938 | HIGH 7.5 | f5 big-ip_advanced_web_application_firewall When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than 1024 characters in length for the Data Guard Protection Enforcement setting, either manually or through the automatic Policy Builder, the bd process can terminate repeatedl | 0,3% | — |
| CVE-2025-59781 | HIGH 7.5 | f5 big-ip_access_policy_manager When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undisclosed DNS queries can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,3% | — |
| CVE-2025-58120 | HIGH 7.5 | f5 big-ip_next_cloud-native_network_functions When HTTP/2 Ingress is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,3% | — |
| CVE-2025-58096 | HIGH 7.5 | f5 big-ip_access_policy_manager When the database variable tm.tcpudptxchecksum is configured as non-default value Software-only on a BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technica | 0,3% | — |
| CVE-2025-55036 | HIGH 7.5 | f5 big-ip_ssl_orchestrator When BIG-IP SSL Orchestrator explicit forward proxy is configured on a virtual server and the proxy connect feature is enabled, undisclosed traffic may cause memory corruption. Note: Software versions which have reached End of Technical Support (EoTS) are not | 0,3% | — |
| CVE-2025-54858 | HIGH 7.5 | f5 big-ip_advanced_web_application_firewall When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed JSON schema, and the security policy is applied to a virtual server, undisclosed requests can cause the bd process to terminate. Note: Sof | 0,3% | — |
| CVE-2025-54854 | HIGH 7.5 | f5 big-ip_access_policy_manager When a BIG-IP APM OAuth access profile (Resource Server or Resource Client) is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not eval | 0,3% | — |
| CVE-2025-54479 | HIGH 7.5 | f5 big-ip_next_cloud-native_network_functions When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) | 0,3% | — |
| CVE-2025-53856 | HIGH 7.5 | f5 big-ip_access_policy_manager When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object uses the embedded Packet Velocity Acceleration (ePVA) feature, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to termin | 0,3% | — |
| CVE-2025-53474 | HIGH 7.5 | f5 big-ip_access_policy_manager When an iRule using an ILX::call command is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,3% | — |
| CVE-2025-41430 | HIGH 7.5 | f5 big-ip_ssl_orchestrator When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,3% | — |
| CVE-2024-10318 | MED 5.4 | f5 nginx_api_connectivity_manager A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled account. As a result, although the attac | 0,3% | — |
| CVE-2023-22418 | MED 6.1 | f5 big-ip_access_policy_manager On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows a | 0,3% | — |
| CVE-2022-1389 | LOW 3.1 | f5 big-ip_access_policy_manager On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP (fixed in 17.0.0), a cross-site request forgery (CSRF) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. This vulnerability allows an attacker to | 0,3% | — |
| CVE-2020-5908 | MED 5.5 | f5 big-ip_access_policy_manager In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in the local log files. | 0,3% | — |
| CVE-2019-6633 | MED 4.4 | f5 big-ip_access_policy_manager On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, and 11.5.1-11.6.4, when the BIG-IP system is licensed with Appliance mode, user accounts with Administrator and Resource Administrator roles can bypass Appliance mode restrictions. | 0,3% | — |
| CVE-2019-6648 | MED 4.4 | f5 container_ingress_service On version 1.9.0, If DEBUG logging is enable, F5 Container Ingress Service (CIS) for Kubernetes and Red Hat OpenShift (k8s-bigip-ctlr) log files may contain BIG-IP secrets such as SSL Private Keys and Private key Passphrases as provided as inputs by an AS3 Dec | 0,3% | — |
| CVE-2026-40701 | MED 4.8 | f5 dos NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With thi | 0,3% | — |
| CVE-2026-32647 | HIGH 7.8 | f5 nginx_open_source NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a speci | 0,3% | — |
| CVE-2024-23979 | HIGH 7.5 | f5 big-ip_access_policy_manager When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource utilization. Note: Software versions which ha | 0,3% | — |