← Back

F5

f5

1,032 CVEs • 284 products

Products (284)

Click to collapse
Toggle
Nginx
nginx
Njs
njs
Nginx Plus
nginx_plus
Big Iq Cloud
big-iq_cloud
Big Iq Device
big-iq_device
F5os A
f5os-a
Iworkflow
iworkflow
Big Ip Dns
big-ip_dns
F5os C
f5os-c
Firepass
firepass
Tmos
tmos
Firepass 4100
firepass_4100
Big Iq Adc
big-iq_adc
Dos
dos
Waf
waf
Arx
arx
Arx Firmware
arx_firmware
F5 Iworkflow
f5_iworkflow
Big Ip
big-ip
Big Ip Edge
big-ip_edge
Big Ip Ltm
big-ip_ltm
Big Ip Afm
big-ip_afm
Big Ip Apm
big-ip_apm
Big Ip Asm
big-ip_asm
Big Ip Pem
big-ip_pem
Websafe
websafe
Nginx Unit
nginx_unit
Nginx Agent
nginx_agent
Big Ip Next
big-ip_next
Firepass 1000
firepass_1000
Firepass 1200
firepass_1200
Big Ip 1000
big-ip_1000
Big Ip 11000
big-ip_11000

CVEs (1,032)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1F5
14Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+11 more
Jun 17, 2026
Aug 26, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
In versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, the BIG-IP Client or Server SSL profile ignores revoked certificates, even when a valid CRL is present. This impacts SS...Show more
In versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, the BIG-IP Client or Server SSL profile ignores revoked certificates, even when a valid CRL is present. This impacts SSL/TLS connections and may result in a man-in-the-middle attack on the connections.Show less
1F5
14Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+11 more
Jun 17, 2026
Aug 26, 2020
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the restjavad process's dump command does not follow current best coding practices and may over...Show more
In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the restjavad process's dump command does not follow current best coding practices and may overwrite arbitrary files.Show less
1F5
1Njs
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
njs through 0.4.3, used in NGINX, allows control-flow hijack in njs_value_property in njs_value.c. NOTE: the vendor considers the issue to be "fluff" in the NGINX use case because there is no remote attack surface.
1F5
1Njs
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_json_stringify_iterator in njs_json.c.
1F5
1Njs
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_lvlhsh_level_find in njs_lvlhsh.c.
1F5
1Njs
Jun 17, 2026
Aug 13, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
njs through 0.4.3, used in NGINX, has a use-after-free in njs_json_parse_iterator_call in njs_json.c.
1F5
1Nginx Controller
Jun 17, 2026
Jul 2, 2020
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL On Debian/Ubuntu system.
1F5
1Nginx Controller
Jun 17, 2026
Jul 2, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection woul...Show more
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.Show less
1F5
1Nginx Controller
Jun 17, 2026
Jul 2, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.
1F5
1Big Ip Access Policy Manager
Jun 17, 2026
Jul 1, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in the local log files.
1F5
11Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+8 more
Jun 17, 2026
Jul 1, 2020
N/A· v4
7.2 HIGH· v3
6.0 MEDIUM· v2
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, an authorized user provided with access only to the TMOS Shell (tmsh) may be able to conduct arbitrary file read...Show more
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, an authorized user provided with access only to the TMOS Shell (tmsh) may be able to conduct arbitrary file read/writes via the built-in sftp functionality.Show less
1F5
11Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+8 more
Jun 17, 2026
Jul 1, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
In versions 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, the BIG-IP system does not properly enforce the access controls for the scp.blacklist files. This allows Admin and Resource Admin users with Secure Copy...Show more
In versions 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, the BIG-IP system does not properly enforce the access controls for the scp.blacklist files. This allows Admin and Resource Admin users with Secure Copy (SCP) protocol access to read and overwrite blacklisted files via SCP.Show less
1F5
11Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+8 more
Jun 17, 2026
Jul 1, 2020
N/A· v4
4.3 MEDIUM· v3
6.0 MEDIUM· v2
In version 11.6.1-11.6.5.2 of the BIG-IP system Configuration utility Network > WCCP page, the system does not sanitize all user-provided data before display.
1F5
11Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+8 more
Jun 17, 2026
Jul 1, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a cross-site request forgery (CSRF) vulnerability in the Traffic Management User Interface (TMUI), also referred to as the Configurat...Show more
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a cross-site request forgery (CSRF) vulnerability in the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, exists in an undisclosed page.Show less
1F5
11Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+8 more
Jun 17, 2026
Jul 1, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.
1F5
14Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+11 more
Jun 17, 2026
Jul 1, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code E...Show more
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.Show less
1F5
1Nginx Controller
Jun 17, 2026
Jul 1, 2020
N/A· v4
9.6 CRITICAL· v3
9.3 HIGH· v2
In NGINX Controller 3.3.0-3.4.0, undisclosed API endpoints may allow for a reflected Cross Site Scripting (XSS) attack. If the victim user is logged in as admin this could result in a complete compromise of the system.
1F5
1Nginx Controller
Jun 17, 2026
Jul 1, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database connection or have read...Show more
In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database connection or have read access to the database, to request a password reset using the email address of another registered user then retrieve the recovery code.Show less
1F5
1Nginx Controller
Jun 17, 2026
Jul 1, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In versions 3.0.0-3.4.0, 2.0.0-2.9.0, and 1.0.1, there is insufficient cross-site request forgery (CSRF) protections for the NGINX Controller user interface.
1F5
2Big Ip Access Policy Manager
Big Ip Access Policy Manager Client
Jun 17, 2026
May 12, 2020
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
In versions 7.1.5-7.1.9, BIG-IP Edge Client Windows Stonewall driver does not sanitize the pointer received from the userland. A local user on the Windows client system can send crafted DeviceIoControl requests to \\.\ur...Show more
In versions 7.1.5-7.1.9, BIG-IP Edge Client Windows Stonewall driver does not sanitize the pointer received from the userland. A local user on the Windows client system can send crafted DeviceIoControl requests to \\.\urvpndrv device causing the Windows kernel to crash.Show less