F5
f5
1,032 CVEs • 284 products
Products (284)
Click to collapseToggle
Products (284)
Click to collapse
CVEs (1,032)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 29, 2026 May 13, 2026 6.9 MEDIUM· v4 6.8 MEDIUM· v3 N/A· v2 When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that may allow an authenticated attacker with administrator role privileges to cross a security boundary...Show more |
1F5 1Big Iq Centralized Management Jun 29, 2026 May 13, 2026 7.2 HIGH· v4 8.1 HIGH· v3 N/A· v2 An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system. Note: Software versions which have reached End of Technica...Show more |
1F5 2Nginx Open Source Nginx PlusJul 15, 2026 Mar 24, 2026 8.5 HIGH· v4 7.8 HIGH· v3 N/A· v2 NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination o...Show more |
1F5 2Nginx Open Source Nginx PlusJun 17, 2026 Mar 24, 2026 5.3 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, all...Show more |
1F5 2Nginx Open Source Nginx PlusJun 17, 2026 Mar 24, 2026 6.3 MEDIUM· v4 3.7 LOW· v3 N/A· v2 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary...Show more |
The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a spe...Show more |
1F5 2Nginx Open Source Nginx PlusJul 15, 2026 Mar 24, 2026 8.8 HIGH· v4 8.2 HIGH· v3 N/A· v2 NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination...Show more |
1F5 2Nginx Open Source Nginx PlusJul 15, 2026 Mar 24, 2026 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enab...Show more |
1F5 1Big Ip Container Ingress Services Jun 17, 2026 Feb 4, 2026 6.9 MEDIUM· v4 4.9 MEDIUM· v3 N/A· v2 A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secrets. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
1F5 2Big Ip Advanced Web Application Firewall Big Ip Application Security ManagerJun 17, 2026 Feb 4, 2026 8.2 HIGH· v4 5.9 MEDIUM· v3 N/A· v2 When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions beyond the attacker's control can cause the bd process to terminate. Note: Software version...Show more |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 17, 2026 Feb 4, 2026 2.3 LOW· v4 4.3 MEDIUM· v3 N/A· v2 A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated...Show more |
1F5 2Big Ip Access Policy Manager Big Ip Access Policy Manager ClientJun 17, 2026 Feb 4, 2026 2.0 LOW· v4 3.3 LOW· v3 N/A· v2 A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attackers to gain access to sensitive information. Note: Software versions which have reached End of Technical Support (EoTS...Show more |
1F5 5Nginx Gateway Fabric Nginx Ingress ControllerNginx Instance Manager+2 moreJun 17, 2026 Feb 4, 2026 8.2 HIGH· v4 5.9 MEDIUM· v3 N/A· v2 A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with...Show more |
A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
1F5 24Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+21 moreJun 17, 2026 Oct 15, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 When using a multi-bladed platform with more than one blade, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS...Show more |
1F5 2Big Ip Advanced Web Application Firewall Big Ip Application Security ManagerJun 17, 2026 Oct 15, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS)...Show more |
1F5 1Big Ip Access Policy Manager Jun 17, 2026 Oct 15, 2025 5.1 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM that allows an attacker to run JavaScript in the context of the targeted logged-out user. Note: Software versions which ha...Show more |
1F5 23Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+20 moreJun 17, 2026 Oct 15, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not eval...Show more |
A vulnerability exists in F5OS-A and F5OS-C system that may allow an authenticated attacker with local access to escalate their privileges. A successful exploit may allow the attacker to cross a security boundary. Note...Show more |
A vulnerability exists in F5OS-A software that allows a highly privileged authenticated attacker to access sensitive FIPS hardware security module (HSM) information on F5 rSeries systems. Note: Software versions which h...Show more |