Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2022-29473
On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when an IPSec ALG profile is …
Big Ip Access Policy Manager
Mitigation only
HIGH 7.2
CVE-2022-28695
On F5 BIG-IP AFM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior t…
Big Ip Advanced Firewall Manager
Mitigation only
MEDIUM 6.5
CVE-2022-28859
On F5 BIG-IP 15.1.x versions prior to 15.1.5.1 and 14.1.x versions prior to 14.1.4.6, when installing Net HSM, the scripts (nethsm-safenet-install.sh…
Big Ip Access Policy Manager
Mitigation only
MEDIUM 5.9
CVE-2022-28708
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, when a BIG-IP DNS resolver-enabled, HTTP-Explicit or SOCKS prof…
Big Ip Access Policy Manager
Mitigation only
MEDIUM 5.4
CVE-2022-28707
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, a stored cross-site scripti…
Big Ip Access Policy Manager
Mitigation only
HIGH 7.2
CVE-2022-27806
On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC…
Big Ip Access Policy Manager
9.0+
MEDIUM 6.8
CVE-2022-27878
On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0…
Big Ip Access Policy Manager
Mitigation only
MEDIUM 5.5
CVE-2022-27636
On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13…
Big Ip Access Policy Manager
after 7.2.1
MEDIUM 5.5
CVE-2022-27875
On F5 Access for Android 3.x versions prior to 3.0.8, a Task Hijacking vulnerability exists in the F5 Access for Android application, which may allow…
Access For Android
3.0.8+
CRITICAL 9.1
CVE-2022-26415
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5…
Big Ip Access Policy Manager
13.1.5 / 14.1.4.6+
HIGH 7.5
CVE-2022-26517
On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when the BIG-IP CGNAT Large S…
Big Ip Access Policy Manager
Mitigation only
HIGH 7.5
CVE-2022-26890
On F5 BIG-IP Advanced WAF, ASM, and APM 16.1.x versions prior to 16.1.2.1, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and 13…
Big Ip Access Policy Manager
Mitigation only
HIGH 7.5
CVE-2022-27189
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5…
Big Ip Access Policy Manager
Mitigation only
HIGH 7.2
CVE-2022-27634
On 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, BIG-IP APM does not properly validate configurations, allowing an authent…
Big Ip Access Policy Manager
15.1.5.1 / 16.1.2.2+
MEDIUM 6.5
CVE-2022-27495
On all versions 1.3.x (fixed in 1.4.0) NGINX Service Mesh control plane endpoints are exposed to the cluster overlay network. Note: Software versions…
Nginx Service Mesh
Mitigation only
MEDIUM 6.1
CVE-2022-27230
On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP APM, and F5 BIG-IP Guided Configuration (GC) all versions prior to…
Big Ip Access Policy Manager
9.0+
MEDIUM 5.3
CVE-2022-27181
On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13…
Big Ip Access Policy Manager
Mitigation only
MEDIUM 5.3
CVE-2022-27182
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, when BIG-IP packet filters …
Big Ip Access Policy Manager
No fix yet
HIGH 7.5
CVE-2022-26071
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5…
Big Ip Access Policy Manager
Mitigation only
HIGH 7.5
CVE-2022-26370
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, and 14.1.x versions prior to 14.1.4.6, when a Session Initiation Pro…
Big Ip Access Policy Manager
Mitigation only
HIGH 7.5
CVE-2022-26372
On F5 BIG-IP 15.1.x versions prior to 15.1.0.2, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11…
Big Ip Access Policy Manager
Mitigation only
MEDIUM 6.5
CVE-2022-25946
On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC…
Big Ip Access Policy Manager
after 9.0
MEDIUM 5.3
CVE-2022-25990
On 1.0.x versions prior to 1.0.1, systems running F5OS-A software may expose certain registry ports externally. Note: Software versions which have re…
F5os A
No fix yet
MEDIUM 5.3
CVE-2022-26130
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13…
Big Ip Access Policy Manager
Mitigation only
CRITICAL 9.8
CVE-2022-1388 KEVEPSS 100%
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5…
Big Ip Access Policy Manager
13.1.5 / 14.1.4.6+
MEDIUM 6.5
CVE-2021-23055
On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not appl…
Nginx Ingress Controller
1.12.3 / 2.0.3+
MEDIUM 5.5
CVE-2022-28049
NGINX NJS 0.7.2 was discovered to contain a NULL pointer dereference via the component njs_vmcode_array at /src/njs_vmcode.c.
Njs
Patch available
CRITICAL 9.8
CVE-2022-27007
nginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a restored frame saved with njs_func…
Njs
Patch available
HIGH 7.5
CVE-2022-27008
nginx njs 0.7.2 is vulnerable to Buffer Overflow. Type confused in Array.prototype.concat() when a slow array appended element is fast array.
Njs
Patch available
HIGH 7.4
CVE-2021-3618
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certif…
Nginx
1.21.0 / 3.0.4+