Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-41225 A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration obj… Big Ip Access Policy Manager after 17.5.1 Fix from $2,3002026-05-13 HIGH 7.9 CVE-2026-41217 A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or adm… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-41218 When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the ur… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-41227 On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in memory consumption causing the T… Big Ip Advanced Web Application Firewall after 17.5.1 Fix from $1,9502026-05-13 MEDIUM 6.5 CVE-2026-41219 An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a… Big Ip Access Policy Manager after 17.5.1 Fix from $1,6002026-05-13 MEDIUM 5.4 CVE-2026-40703 A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility.  Note: Software versions which have re… Big Ip Access Policy Manager after 17.5.1 Fix from $1,6002026-05-13 HIGH 8.7 CVE-2026-40631 An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in p… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 HIGH 8.7 CVE-2026-40698 A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role c… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-40618 When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-40629 When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections.  No… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 MEDIUM 6.5 CVE-2026-40699 A vulnerability exists in the undisclosed pages in the Configuration utility that may allow a low-privileged authenticated attacker to access to undi… Big Ip Access Policy Manager after 17.5.1 Fix from $1,6002026-05-13 HIGH 8.7 CVE-2026-40061 When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authent… Big Ip Domain Name System after 17.5.1 Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-40060 When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.  … Big Ip Application Security Manager after 17.5.1 Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-40067 When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate.  Note: Software vers… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-40423 When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: So… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 MEDIUM 6.5 CVE-2026-40460 When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing … Dos after 5.12.1 Fix from $1,6002026-05-13 MEDIUM 6.5 CVE-2026-40462 Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command which may allow an authenticated att… Big Ip Access Policy Manager after 17.5.1 Fix from $1,6002026-05-13 MEDIUM 5.3 CVE-2026-40435 When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blocked addresses.  Note: Softwa… Big Ip Access Policy Manager after 17.5.1 Fix from $1,6002026-05-13 HIGH 7.5 CVE-2026-39455 When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, undisclosed traffic can cause… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-39458 When a BIG-IP DNS profile enabled with DNS cache is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel … Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 HIGH 7.2 CVE-2026-39459 A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with at least the Manager role ca… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 MEDIUM 6.5 CVE-2026-35062 An authenticated iControl SOAP user may be able to obtain information of other accounts.  Note: Software versions which have reached End of Technica… Big Ip Access Policy Manager after 17.5.1 Fix from $1,6002026-05-13 HIGH 8.7 CVE-2026-32643 A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can … Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 HIGH 8.7 CVE-2026-32673 A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to … Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 HIGH 8.7 CVE-2026-34176 When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 MEDIUM 5.3 CVE-2026-34019 When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic can cause the Traffic Manage… Big Ip Access Policy Manager after 17.1.2 Fix from $1,6002026-05-13 HIGH 8.1 CVE-2026-20916 An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG… Big Iq Centralized Management Mitigation only Fix from $1,9502026-05-13 MEDIUM 6.8 CVE-2026-24464 When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that may allow an authenticated a… Big Ip Access Policy Manager after 17.5.1 Fix from $1,6002026-05-13 HIGH 7.8 CVE-2026-32647 NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read … Nginx Plus 1.28.3 / 1.29.7+ Fix from $1,9502026-03-24 HIGH 8.2 CVE-2026-27654EPSS 22% NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to … Nginx Plus 1.28.3 / 1.29.7+ Fix from $1,9502026-03-24