Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2017-20005
NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes a…
Nginx
1.13.6+
MEDIUM 5.5
CVE-2021-23021
The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with current permission bits set to…
Nginx Controller
3.7.0+
HIGH 7.8
CVE-2021-23019
The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is included in the NGI…
Nginx Controller
3.15.0+
HIGH 7.7
CVE-2021-23017EPSS 53%
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte…
Nginx
1.19.3.2 / 1.20.1+
MEDIUM 5.5
CVE-2021-23020
The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which could lead to predictable keys.
Nginx Controller
3.10.0+
HIGH 7.4
CVE-2021-23018
Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are using cleartext protocols insid…
Nginx Controller
after 3.4.0
HIGH 8.8
CVE-2021-23014
On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, and 14.1.x before 14.1.4, BIG-IP Advanced WAF and ASM are missing authorization checks for …
Big Ip Advanced Web Application Firewall
14.1.4 / 15.1.3+
HIGH 8.2
CVE-2021-23012
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x before 13.1.4, lack of input validation for items u…
Big Ip Access Policy Manager
13.1.4 / 14.1.4+
HIGH 7.5
CVE-2021-23009
On BIG-IP version 16.0.x before 16.0.1.1 and 15.1.x before 15.1.3, malformed HTTP/2 requests may cause an infinite loop which causes a Denial of Serv…
Big Ip Access Policy Manager
15.1.3 / 16.0.1.1+
HIGH 7.5
CVE-2021-23010
On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and 12.1.x before 12.1.5.3, when the BIG-IP…
Big Ip Application Security Manager
after 16.0.1.1
HIGH 7.2
CVE-2021-23015
On BIG-IP 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.0.8 through 13.1.3.6, and all versions of 16.0.x, when running in Appliance Mode, an aut…
Big Ip Access Policy Manager
13.1.4 / 14.1.4+
MEDIUM 5.3
CVE-2021-23016
On BIG-IP APM versions 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, and all versions of 16.0.x, 12.1.x, and 11.6.x, an attacke…
Big Ip Access Policy Manager
13.1.4 / 14.1.4.1+
CRITICAL 9.8
CVE-2021-23008
On version 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and all versions of 16.0.x and 11.6.x., BIG-IP APM…
Big Ip Access Policy Manager
11.6.5 / 12.1.5+
HIGH 7.5
CVE-2021-23011
On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and 11.6.x before 11.6.5.…
Big Ip Access Policy Manager
11.6.5.3 / 12.1.6+
HIGH 7.5
CVE-2021-23013
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, the Traffi…
Big Ip Access Policy Manager
12.1.5.3 / 13.1.4+
CRITICAL 9.1
CVE-2021-23005
On all 7.x and 6.x versions (fixed in 8.0.0), when using a Quorum device for BIG-IQ high availability (HA) for automatic failover, BIG-IQ does not ma…
Big Iq Centralized Management
8.0.0+
HIGH 7.5
CVE-2021-22997
On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ HA ElasticSearch service does not implement any form of authentication for the clustering transp…
Big Iq Centralized Management
8.0.0+
HIGH 7.5
CVE-2021-22999
On versions 15.0.x before 15.1.0 and 14.1.x before 14.1.4, the BIG-IP system provides an option to connect HTTP/2 clients to HTTP/1.x servers. When a…
Big Ip Access Policy Manager
14.1.4 / 15.1.0+
HIGH 7.5
CVE-2021-23000
On BIG-IP versions 13.1.3.4-13.1.3.6 and 12.1.5.2, if the tmm.http.rfc.enforcement BigDB key is enabled in a BIG-IP system, or the Bad host header va…
Big Ip Access Policy Manager
13.1.3.6+
HIGH 7.5
CVE-2021-23003
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x b…
Big Ip Access Policy Manager
11.6.5.3 / 12.1.5.3+
HIGH 7.5
CVE-2021-23004
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x b…
Big Ip Access Policy Manager
11.6.5.3 / 12.1.5.3+
MEDIUM 6.1
CVE-2021-23006
On all 7.x and 6.x versions (fixed in 8.0.0), undisclosed BIG-IQ pages have a reflected cross-site scripting vulnerability. Note: Software versions w…
Big Iq Centralized Management
8.0.0+
MEDIUM 5.3
CVE-2021-22998
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x b…
Big Ip Access Policy Manager
11.6.5.3 / 12.1.5.3+
MEDIUM 5.3
CVE-2021-23007
On BIG-IP versions 14.1.4 and 16.0.1.1, when the Traffic Management Microkernel (TMM) process handles certain undisclosed traffic, it may start dropp…
Big Ip Access Policy Manager
Patch available
CRITICAL 9.8
CVE-2021-22991 KEVEPSS 61%
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclo…
Big Ip Access Policy Manager
12.1.5.3 / 13.1.3.6+
HIGH 8.8
CVE-2021-22993
On BIG-IP Advanced WAF and BIG-IP ASM versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, and 12.1…
Big Ip Advanced Web Application Firewall
12.1.5.3 / 13.1.3.6+
HIGH 7.5
CVE-2021-22996
On all 7.x versions (fixed in 8.0.0), when set up for auto failover, a BIG-IQ Data Collection Device (DCD) cluster member that receives an undisclose…
Big Iq Centralized Management
8.0.0+
MEDIUM 6.1
CVE-2021-22994
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x b…
Big Ip Access Policy Manager
11.6.5.3 / 12.1.5.3+
CRITICAL 9.8
CVE-2021-22992EPSS 73%
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x b…
Big Ip Access Policy Manager
11.6.5.3 / 12.1.5.3+
HIGH 7.5
CVE-2021-22995
On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ high availability (HA) when using a Quorum device for automatic failover does not implement any …
Big Iq Centralized Management
after 7.1.0