58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
Vulnerabilità F5
1039 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-32643 | HIGH 8.7 | f5 big-ip_access_policy_manager A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached | 0,3% | — |
| CVE-2020-5898 | MED 5.5 | f5 big-ip_access_policy_manager In versions 7.1.5-7.1.9, BIG-IP Edge Client Windows Stonewall driver does not sanitize the pointer received from the userland. A local user on the Windows client system can send crafted DeviceIoControl requests to \\.\urvpndrv device causing the Windows kernel | 0,3% | — |
| CVE-2026-42058 | MED 4.3 | f5 big-ip_access_policy_manager An authenticated attacker's undisclosed requests to BIG-IP iControl REST can lead to an information leak of BIG-IP local user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,3% | — |
| CVE-2021-23020 | MED 5.5 | f5 nginx_controller The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which could lead to predictable keys. | 0,3% | — |
| CVE-2026-42406 | HIGH 8.7 | f5 big-ip_access_policy_manager A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reac | 0,3% | — |
| CVE-2025-54809 | HIGH 7.4 | f5 f5_access F5 Access for Android before version 3.1.2 which uses HTTPS does not verify the remote endpoint identity. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,3% | — |
| CVE-2025-61955 | HIGH 8.8 | f5 f5os-a A vulnerability exists in F5OS-A and F5OS-C systems that may allow an authenticated attacker with local access to escalate their privileges. A successful exploit may allow the attacker to cross a security boundary. Note: Software versions which have reached | 0,2% | — |
| CVE-2025-58424 | MED 5.3 | f5 big-ip_access_policy_manager On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols which do not have message integrity protection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,2% | — |
| CVE-2023-41964 | MED 4.3 | f5 big-ip_access_policy_manager The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,2% | — |
| CVE-2021-23019 | HIGH 7.8 | f5 nginx_controller The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is included in the NGINX support package. | 0,2% | — |
| CVE-2025-61951 | HIGH 7.5 | f5 big-ip_access_policy_manager Undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. This issue may occur when a Datagram Transport Layer Security (DTLS) 1.2 virtual server is enabled with a Server SSL profile that is configured with a certificate, key, and t | 0,2% | — |
| CVE-2024-33612 | MED 6.8 | f5 big-ip_next_central_manager An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,2% | — |
| CVE-2022-27636 | MED 5.5 | f5 big-ip_access_policy_manager On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, as well as F5 BIG-IP APM Clients 7.x versions prior to 7.2.1.5, BI | 0,2% | — |
| CVE-2026-63020 | LOW 3.1 | f5 big-ip_access_policy_manager A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message i | 0,2% | — |
| CVE-2025-58153 | MED 5.9 | f5 big-ip_access_policy_manager Under undisclosed traffic conditions along with conditions beyond the attacker's control, hardware systems with a High-Speed Bridge (HSB) may experience a lockup of the HSB. Note: Software versions which have reached End of Technical Support (EoTS) are not e | 0,2% | — |
| CVE-2021-23021 | MED 5.5 | f5 nginx_controller The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with current permission bits set to 644. | 0,2% | — |
| CVE-2021-23022 | HIGH 7.8 | f5 big-ip_access_policy_manager On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, the BIG-IP Edge Client Windows Installer Service's temporary folder has weak file and folder permissions. Note: Software versions which have reached End of Technical Support (EoTS) are not ev | 0,2% | — |
| CVE-2022-41743 | HIGH 7.0 | f5 nginx_ingress_controller NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_hls_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its crash or potential other impact using a specially crafted audio or video file | 0,2% | — |
| CVE-2023-22372 | MED 5.9 | f5 big-ip_access_policy_manager In the pre connection stage, an improper enforcement of message integrity vulnerability exists in BIG-IP Edge Client for Windows and Mac OS. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,2% | — |
| CVE-2023-1550 | MED 5.5 | f5 nginx_agent Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to private k | 0,2% | — |
| CVE-2023-22358 | HIGH 7.8 | f5 big-ip_access_policy_manager In versions beginning with 7.2.2 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client Windows Installer. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,2% | — |
| CVE-2025-60015 | MED 5.7 | f5 f5os-a An out-of-bounds write vulnerability exists in F5OS-A and F5OS-C that could lead to memory corruption. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,2% | — |
| CVE-2022-29263 | HIGH 7.8 | f5 access_policy_manager_clients On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, as well as F5 BIG-IP APM Clients 7.x versions prior to 7.2.1.5, th | 0,2% | — |
| CVE-2025-57780 | HIGH 8.8 | f5 f5os-a A vulnerability exists in F5OS-A and F5OS-C system that may allow an authenticated attacker with local access to escalate their privileges. A successful exploit may allow the attacker to cross a security boundary. Note: Software versions which have reached E | 0,2% | — |
| CVE-2019-6670 | MED 4.4 | f5 big-ip_access_policy_manager On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5, vCMP hypervisors are incorrectly exposing the plaintext unit key for their vCMP guests on the filesystem. | 0,2% | — |