Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2025-35995
When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or an iRule with the urlcat command is enabled on a v…
Big Ip Policy Enforcement Manager
15.1.10.7.0.4.5 / 16.1.6+
HIGH 7.5
CVE-2025-36504
When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization…
Big Ip Access Policy Manager
16.1.6 / 17.1.2+
HIGH 7.5
CVE-2025-36525
When a BIG-IP APM virtual server is configured to use a PingAccess profile, undisclosed requests can cause TMM to terminate.
Note: Software versio…
Big Ip Access Policy Manager
15.1.10.7.0.4.5 / 16.1.6+
HIGH 8.7
CVE-2025-31644EPSS 24%
When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which m…
Big Ip Access Policy Manager
15.1.10.7 / 16.1.6+
MEDIUM 5.3
CVE-2025-1695
In NGINX Unit before version 1.34.2 with the Java Language Module in use, undisclosed requests can lead to an infinite loop and cause an increase in …
Nginx Unit
1.34.2+
HIGH 7.5
CVE-2025-24326
When BIG-IP Advanced WAF/ASM Behavioral DoS (BADoS) TLS Signatures feature is configured, undisclosed traffic can case an increase in memory resource…
Big Ip Application Security Manager
15.1.10.6.0.11.6-ENG / 16.1.5+
HIGH 7.5
CVE-2025-24497
When URL categorization is configured on a virtual server, undisclosed requests can cause TMM to terminate. Note: Software versions which have reach…
Big Ip Policy Enforcement Manager
17.1.2+
HIGH 8.0
CVE-2025-24320
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run Ja…
Big Ip Access Policy Manager
15.1.10.6 / 16.1.5.2+
HIGH 7.5
CVE-2025-24312
When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection profile is configured on a virtual server or firewall rule or policy, …
Big Ip Advanced Firewall Manager
1.4.0 / 15.1.10.6.0.11.6+
MEDIUM 6.5
CVE-2025-24319
When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API can cause the BIG-IP Next Central Manager No…
Big Ip Next Central Manager
20.3.0+
HIGH 8.7
CVE-2025-23239
When running in Appliance mode, and logged into a highly-privileged role, an authenticated remote command injection vulnerability exists in an undisc…
Big Ip Access Policy Manager
Mitigation only
HIGH 7.5
CVE-2025-22846
When SIP Session and Router ALG profiles are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Managemen…
Big Ip Next Service Proxy For Kubernetes
1.7.7 / 15.1.10.6.0.11.6-ENG+
HIGH 7.5
CVE-2025-22891
When BIG-IP PEM Control Plane listener Virtual Server is configured with Diameter Endpoint profile, undisclosed traffic can cause the Virtual Server …
Big Ip Policy Enforcement Manager
15.1.10.6.0.11.6 / 16.1.5+
HIGH 7.5
CVE-2025-23412
When BIG-IP APM Access Profile is configured on a virtual server, undisclosed request can cause TMM to terminate.
Note: Software versions whic…
Big Ip Access Policy Manager
16.1.5 / 17.1.2+
HIGH 7.5
CVE-2025-21087
When Client or Server SSL profiles are configured on a Virtual Server, or DNSSEC signing operations are in use, undisclosed traffic can cause an incr…
Big Ip Access Policy Manager
16.1.6 / 17.1.2+
HIGH 7.5
CVE-2025-21091
When SNMP v1 or v2c are disabled on the BIG-IP, undisclosed requests can cause an increase in memory resource utilization.
Note: Software versio…
Big Ip Access Policy Manager
16.1.6 / 17.1.2+
HIGH 8.8
CVE-2025-20029EPSS 7%
Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command, which may allow an authenticated attacker to execu…
Big Ip Access Policy Manager
15.1.10.6 / 16.1.5.2+
HIGH 7.5
CVE-2025-20045
When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile are configured on a Message Routi…
Big Ip Access Policy Manager
16.1.5 / 17.1.2+
HIGH 7.5
CVE-2025-20058
When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. No…
Big Ip Access Policy Manager
16.1.6 / 17.1.2+
MEDIUM 5.4
CVE-2024-10318
A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw …
Nginx Api Connectivity Manager
1.9.3 / 2.17.4+
HIGH 7.2
CVE-2024-45844EPSS 11%
BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings. Note: Software v…
Big Ip Access Policy Manager
15.1.10.5 / 16.1.5+
MEDIUM 6.8
CVE-2024-47139
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the …
Big Iq Centralized Management
Mitigation only
HIGH 7.5
CVE-2024-41164
When TCP profile with Multipath TCP enabled (MPTCP) is configured on a Virtual Server, undisclosed traffic along with conditions beyond the attackers…
Big Ip Access Policy Manager
16.1.5+
HIGH 7.5
CVE-2024-41727
In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using Intel E810 SR-IOV NIC, undisclosed traffic can ca…
Big Ip Access Policy Manager
16.1.5+
MEDIUM 5.5
CVE-2024-41719
When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged in the BIG-IP Centra…
Big Ip Next Central Manager
20.2.1+
HIGH 8.8
CVE-2024-39809
The Central Manager user session refresh token does not expire when a user logs out. Note: Software versions which have reached End of Technical Sup…
Big Ip Next Central Manager
Mitigation only
HIGH 7.5
CVE-2024-39778
When a stateless virtual server is configured on BIG-IP system with a High-Speed Bridge (HSB), undisclosed requests can cause TMM to terminate.
No…
Big Ip Access Policy Manager
16.1.5+
HIGH 7.5
CVE-2024-39792
When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests can cause an increase in memory resource utilization. Note: …
Nginx Plus
Mitigation only
MEDIUM 5.3
CVE-2024-37028
BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in. Note: Software versions which have reached E…
Big Ip Next Central Manager
20.2.1+
MEDIUM 6.5
CVE-2024-32760
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes t…
Nginx Open Source
1.26.1+