Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Big Ip Access Policy Manager HIGH 7.5
CVE-2022-29473

On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when an IPSec ALG profile is …

Mitigation only
Fix from $1,950 2022-05-05
Big Ip Advanced Firewall Manager HIGH 7.2
CVE-2022-28695

On F5 BIG-IP AFM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior t…

Mitigation only
Fix from $1,950 2022-05-05
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2022-28859

On F5 BIG-IP 15.1.x versions prior to 15.1.5.1 and 14.1.x versions prior to 14.1.4.6, when installing Net HSM, the scripts (nethsm-safenet-install.sh…

Mitigation only
Fix from $1,600 2022-05-05
Big Ip Access Policy Manager MEDIUM 5.9
CVE-2022-28708

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, when a BIG-IP DNS resolver-enabled, HTTP-Explicit or SOCKS prof…

Mitigation only
Fix from $1,600 2022-05-05
Big Ip Access Policy Manager MEDIUM 5.4
CVE-2022-28707

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, a stored cross-site scripti…

Mitigation only
Fix from $1,600 2022-05-05
Big Ip Access Policy Manager HIGH 7.2
CVE-2022-27806

On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC…

Fix: 9.0+
Fix from $1,950 2022-05-05
Big Ip Access Policy Manager MEDIUM 6.8
CVE-2022-27878

On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0…

Mitigation only
Fix from $1,600 2022-05-05
Big Ip Access Policy Manager MEDIUM 5.5
CVE-2022-27636

On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13…

Fix: after 7.2.1
Fix from $1,600 2022-05-05
Access For Android MEDIUM 5.5
CVE-2022-27875

On F5 Access for Android 3.x versions prior to 3.0.8, a Task Hijacking vulnerability exists in the F5 Access for Android application, which may allow…

Fix: 3.0.8+
Fix from $1,600 2022-05-05
Big Ip Access Policy Manager CRITICAL 9.1
CVE-2022-26415

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5…

Fix: 13.1.5 / 14.1.4.6+
Fix from $2,300 2022-05-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-26517

On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when the BIG-IP CGNAT Large S…

Mitigation only
Fix from $1,950 2022-05-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-26890

On F5 BIG-IP Advanced WAF, ASM, and APM 16.1.x versions prior to 16.1.2.1, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and 13…

Mitigation only
Fix from $1,950 2022-05-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-27189

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5…

Mitigation only
Fix from $1,950 2022-05-05
Big Ip Access Policy Manager HIGH 7.2
CVE-2022-27634

On 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, BIG-IP APM does not properly validate configurations, allowing an authent…

Fix: 15.1.5.1 / 16.1.2.2+
Fix from $1,950 2022-05-05
Nginx Service Mesh MEDIUM 6.5
CVE-2022-27495

On all versions 1.3.x (fixed in 1.4.0) NGINX Service Mesh control plane endpoints are exposed to the cluster overlay network. Note: Software versions…

Mitigation only
Fix from $1,600 2022-05-05
Big Ip Access Policy Manager MEDIUM 6.1
CVE-2022-27230

On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP APM, and F5 BIG-IP Guided Configuration (GC) all versions prior to…

Fix: 9.0+
Fix from $1,600 2022-05-05
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2022-27181

On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13…

Mitigation only
Fix from $1,600 2022-05-05
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2022-27182

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, when BIG-IP packet filters …

No fix yet
Fix from $1,600 2022-05-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-26071

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5…

Mitigation only
Fix from $1,950 2022-05-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-26370

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, and 14.1.x versions prior to 14.1.4.6, when a Session Initiation Pro…

Mitigation only
Fix from $1,950 2022-05-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-26372

On F5 BIG-IP 15.1.x versions prior to 15.1.0.2, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11…

Mitigation only
Fix from $1,950 2022-05-05
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2022-25946

On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC…

Fix: after 9.0
Fix from $1,600 2022-05-05
F5os A MEDIUM 5.3
CVE-2022-25990

On 1.0.x versions prior to 1.0.1, systems running F5OS-A software may expose certain registry ports externally. Note: Software versions which have re…

No fix yet
Fix from $1,600 2022-05-05
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2022-26130

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13…

Mitigation only
Fix from $1,600 2022-05-05
Big Ip Access Policy Manager CRITICAL 9.8
CVE-2022-1388 KEVEPSS 100%

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5…

Fix: 13.1.5 / 14.1.4.6+
Fix from $2,300 2022-05-05
Nginx Ingress Controller MEDIUM 6.5
CVE-2021-23055

On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not appl…

Fix: 1.12.3 / 2.0.3+
Fix from $1,600 2022-04-21
Njs MEDIUM 5.5
CVE-2022-28049

NGINX NJS 0.7.2 was discovered to contain a NULL pointer dereference via the component njs_vmcode_array at /src/njs_vmcode.c.

Patch available
Fix from $1,600 2022-04-15
Njs CRITICAL 9.8
CVE-2022-27007

nginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a restored frame saved with njs_func…

Patch available
Fix from $2,300 2022-04-14
Njs HIGH 7.5
CVE-2022-27008

nginx njs 0.7.2 is vulnerable to Buffer Overflow. Type confused in Array.prototype.concat() when a slow array appended element is fast array.

Patch available
Fix from $1,950 2022-04-14
Nginx HIGH 7.4
CVE-2021-3618

ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certif…

Fix: 1.21.0 / 3.0.4+
Fix from $1,950 2022-03-23