F5
f5
1,038 CVEs • 284 products
Products (284)
Click to collapseToggle
Products (284)
Click to collapse
CVEs (1,038)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 29, 2026 May 13, 2026 7.1 HIGH· v4 6.5 MEDIUM· v3 N/A· v2 An authenticated iControl SOAP user may be able to obtain information of other accounts.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 29, 2026 May 13, 2026 8.5 HIGH· v4 8.7 HIGH· v3 N/A· v2 When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note:...Show more |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 29, 2026 May 13, 2026 6.3 MEDIUM· v4 5.3 MEDIUM· v3 N/A· v2 When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to stop processing BFD packets and cause the con...Show more |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 29, 2026 May 13, 2026 8.5 HIGH· v4 8.7 HIGH· v3 N/A· v2 A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In appliance...Show more |
1F5 22Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+19 moreJun 29, 2026 May 13, 2026 8.5 HIGH· v4 8.7 HIGH· v3 N/A· v2 A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. No...Show more |
1F5 1Big Ip Domain Name System Jun 29, 2026 May 13, 2026 6.7 MEDIUM· v4 4.4 MEDIUM· v3 N/A· v2 When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return the ssh-password parameter in cleartext in the iControl REST response and is also logged in the audit...Show more |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 29, 2026 May 13, 2026 6.9 MEDIUM· v4 6.8 MEDIUM· v3 N/A· v2 When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that may allow an authenticated attacker with administrator role privileges to cross a security boundary...Show more |
1F5 1Big Iq Centralized Management Jun 29, 2026 May 13, 2026 7.2 HIGH· v4 8.1 HIGH· v3 N/A· v2 An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system. Note: Software versions which have reached End of Technica...Show more |
1F5 2Nginx Open Source Nginx PlusJul 15, 2026 Mar 24, 2026 8.5 HIGH· v4 7.8 HIGH· v3 N/A· v2 NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination o...Show more |
1F5 2Nginx Open Source Nginx PlusJun 17, 2026 Mar 24, 2026 5.3 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, all...Show more |
1F5 2Nginx Open Source Nginx PlusJun 17, 2026 Mar 24, 2026 6.3 MEDIUM· v4 3.7 LOW· v3 N/A· v2 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary...Show more |
The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a spe...Show more |
1F5 2Nginx Open Source Nginx PlusJul 15, 2026 Mar 24, 2026 8.8 HIGH· v4 8.2 HIGH· v3 N/A· v2 NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination...Show more |
1F5 2Nginx Open Source Nginx PlusJul 15, 2026 Mar 24, 2026 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enab...Show more |
1F5 1Big Ip Container Ingress Services Jun 17, 2026 Feb 4, 2026 6.9 MEDIUM· v4 4.9 MEDIUM· v3 N/A· v2 A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secrets. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
1F5 2Big Ip Advanced Web Application Firewall Big Ip Application Security ManagerJun 17, 2026 Feb 4, 2026 8.2 HIGH· v4 5.9 MEDIUM· v3 N/A· v2 When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions beyond the attacker's control can cause the bd process to terminate. Note: Software version...Show more |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 17, 2026 Feb 4, 2026 2.3 LOW· v4 4.3 MEDIUM· v3 N/A· v2 A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated...Show more |
1F5 2Big Ip Access Policy Manager Big Ip Access Policy Manager ClientJun 17, 2026 Feb 4, 2026 2.0 LOW· v4 3.3 LOW· v3 N/A· v2 A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attackers to gain access to sensitive information. Note: Software versions which have reached End of Technical Support (EoTS...Show more |
1F5 5Nginx Gateway Fabric Nginx Ingress ControllerNginx Instance Manager+2 moreJun 17, 2026 Feb 4, 2026 8.2 HIGH· v4 5.9 MEDIUM· v3 N/A· v2 A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with...Show more |
A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |