Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.1
CVE-2026-20916
An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG…
Big Iq Centralized Management
Mitigation only
HIGH 8.3
CVE-2025-14727
A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation.
Note: Software versions which have reached En…
Nginx Ingress Controller
Mitigation only
HIGH 7.5
CVE-2025-41431
When connection mirroring is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate in …
Big Ip Access Policy Manager
Mitigation only
HIGH 8.7
CVE-2025-23239
When running in Appliance mode, and logged into a highly-privileged role, an authenticated remote command injection vulnerability exists in an undisc…
Big Ip Access Policy Manager
Mitigation only
MEDIUM 6.8
CVE-2024-47139
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the …
Big Iq Centralized Management
Mitigation only
HIGH 8.8
CVE-2024-39809
The Central Manager user session refresh token does not expire when a user logs out. Note: Software versions which have reached End of Technical Sup…
Big Ip Next Central Manager
Mitigation only
HIGH 7.5
CVE-2024-39792
When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests can cause an increase in memory resource utilization. Note: …
Nginx Plus
Mitigation only
HIGH 7.5
CVE-2024-33608
When IPsec is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.
Note: Software …
Big Ip Access Policy Manager
No fix yet
HIGH 7.5
CVE-2024-24989
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate.
Note:…
Nginx Open Source
Mitigation only
HIGH 7.4
CVE-2023-45226
The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacke…
Big Ip Next Service Proxy For Kubernetes
Mitigation only
MEDIUM 5.3
CVE-2023-24594
When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization.
N…
Big Ip Access Policy Manager
Mitigation only
HIGH 7.5
CVE-2023-27727
Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_function_frame at src/njs_function.h.
Njs
No fix yet
HIGH 7.5
CVE-2022-34032
Nginx NJS v0.7.5 was discovered to contain a segmentation violation in the function njs_value_own_enumerate at src/njs_value.c.
Njs
No fix yet
HIGH 7.5
CVE-2022-34027
Nginx NJS v0.7.4 was discovered to contain a segmentation violation via njs_value_property at njs_value.c.
Njs
No fix yet
HIGH 7.5
CVE-2022-34028
Nginx NJS v0.7.5 was discovered to contain a segmentation violation via njs_utf8_next at src/njs_utf8.h.
Njs
No fix yet
HIGH 7.5
CVE-2022-34030
Nginx NJS v0.7.5 was discovered to contain a segmentation violation via njs_djb_hash at src/njs_djb_hash.c.
Njs
No fix yet
HIGH 7.5
CVE-2022-34031
Nginx NJS v0.7.5 was discovered to contain a segmentation violation via njs_value_to_number at src/njs_value_conversion.h.
Njs
No fix yet
HIGH 7.5
CVE-2022-29491
On F5 BIG-IP LTM, Advanced WAF, ASM, or APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, an…
Big Ip Access Policy Manager
Mitigation only
MEDIUM 5.3
CVE-2022-29479
On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11…
Big Ip Access Policy Manager
Mitigation only
MEDIUM 5.3
CVE-2022-29480
On F5 BIG-IP 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when multiple route domains are configured, undisclosed requests…
Big Ip Access Policy Manager
Mitigation only
HIGH 7.8
CVE-2022-28714
On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13…
Big Ip Access Policy Manager
Mitigation only
HIGH 7.8
CVE-2022-29263
On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13…
Access Policy Manager Clients
Mitigation only
HIGH 7.5
CVE-2022-28691
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1…
Big Ip Access Policy Manager
Mitigation only
HIGH 7.5
CVE-2022-28701
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, when the stream profile is configured on a virtual server, undisclosed requests can cause an increase…
Big Ip Access Policy Manager
Mitigation only
HIGH 7.5
CVE-2022-28705
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13…
Big Ip Access Policy Manager
Mitigation only
HIGH 7.5
CVE-2022-28706
On F5 BIG-IP 16.1.x versions prior to 16.1.2 and 15.1.x versions prior to 15.1.5.1, when the DNS resolver configuration is used, undisclosed requests…
Big Ip Access Policy Manager
Mitigation only
HIGH 7.5
CVE-2022-29473
On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when an IPSec ALG profile is …
Big Ip Access Policy Manager
Mitigation only
HIGH 7.2
CVE-2022-28695
On F5 BIG-IP AFM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior t…
Big Ip Advanced Firewall Manager
Mitigation only
MEDIUM 6.5
CVE-2022-28859
On F5 BIG-IP 15.1.x versions prior to 15.1.5.1 and 14.1.x versions prior to 14.1.4.6, when installing Net HSM, the scripts (nethsm-safenet-install.sh…
Big Ip Access Policy Manager
Mitigation only
MEDIUM 5.9
CVE-2022-28708
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, when a BIG-IP DNS resolver-enabled, HTTP-Explicit or SOCKS prof…
Big Ip Access Policy Manager
Mitigation only