F5
f5
1,038 CVEs • 284 products
Products (284)
Click to collapseToggle
Products (284)
Click to collapse
CVEs (1,038)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1F5 4Nginx Api Connectivity Manager Nginx Ingress ControllerNginx Instance Manager+1 moreJun 17, 2026 Nov 6, 2024 5.1 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled...Show more |
1F5 1Big Iq Centralized Management Jun 17, 2026 Oct 16, 2024 4.8 MEDIUM· v4 6.8 MEDIUM· v3 N/A· v2 A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run JavaScript in the context of the currently lo...Show more |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 17, 2026 Oct 16, 2024 8.6 HIGH· v4 7.2 HIGH· v3 N/A· v2 BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings. Note: Software versions which have reached End of Technical Support (EoTS) are not eval...Show more |
1F5 2Nginx Agent Nginx Instance ManagerJun 17, 2026 Aug 22, 2024 6.9 MEDIUM· v4 4.9 MEDIUM· v3 N/A· v2 NGINX Agent's "config_dirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwrite files outside of the designated secure directory. |
1F5 2Nginx Open Source Nginx PlusJun 17, 2026 Aug 14, 2024 5.7 MEDIUM· v4 4.7 MEDIUM· v3 N/A· v2 NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue...Show more |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 17, 2026 Aug 14, 2024 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using Intel E810 SR-IOV NIC, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versi...Show more |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 17, 2026 Aug 14, 2024 5.3 MEDIUM· v4 4.3 MEDIUM· v3 N/A· v2 Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
1F5 1Big Ip Next Central Manager Jun 17, 2026 Aug 14, 2024 5.1 MEDIUM· v4 5.5 MEDIUM· v3 N/A· v2 When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged in the BIG-IP Central Manager logs. Note: Software versions which have reached End of Tech...Show more |
1F5 23Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+20 moreJun 17, 2026 Aug 14, 2024 8.2 HIGH· v4 7.5 HIGH· v3 N/A· v2 When TCP profile with Multipath TCP enabled (MPTCP) is configured on a Virtual Server, undisclosed traffic along with conditions beyond the attackers control can cause TMM to terminate. Note: Software versions which...Show more |
1F5 1Big Ip Next Central Manager Jun 17, 2026 Aug 14, 2024 8.9 HIGH· v4 8.8 HIGH· v3 N/A· v2 The Central Manager user session refresh token does not expire when a user logs out. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated |
When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) ar...Show more |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 17, 2026 Aug 14, 2024 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 When a stateless virtual server is configured on BIG-IP system with a High-Speed Bridge (HSB), undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS...Show more |
1F5 1Big Ip Next Central Manager Jun 17, 2026 Aug 14, 2024 6.3 MEDIUM· v4 5.3 MEDIUM· v3 N/A· v2 BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
2F5 Fedoraproject3Fedora Nginx Open SourceNginx PlusJun 17, 2026 May 29, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate. |
2F5 Fedoraproject3Fedora Nginx Open SourceNginx PlusJun 17, 2026 May 29, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can c...Show more |
2F5 Fedoraproject3Fedora Nginx Open SourceNginx PlusJun 17, 2026 May 29, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause or other potential impact. |
2F5 Fedoraproject3Fedora Nginx Open SourceNginx PlusJun 17, 2026 May 29, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be...Show more |
An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system. Note: Software versions which have reached End of Technical Su...Show more |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 17, 2026 May 8, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 When IPsec is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not eva...Show more |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 17, 2026 May 8, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Softwar...Show more |