Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2025-35995 When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or an iRule with the urlcat command is enabled on a v… Big Ip Policy Enforcement Manager 15.1.10.7.0.4.5 / 16.1.6+ Fix from $1,9502025-05-07 HIGH 7.5 CVE-2025-36504 When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization… Big Ip Access Policy Manager 16.1.6 / 17.1.2+ Fix from $1,9502025-05-07 HIGH 7.5 CVE-2025-36525 When a BIG-IP APM virtual server is configured to use a PingAccess profile, undisclosed requests can cause TMM to terminate. Note: Software versio… Big Ip Access Policy Manager 15.1.10.7.0.4.5 / 16.1.6+ Fix from $1,9502025-05-07 HIGH 8.7 CVE-2025-31644EPSS 24% When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which m… Big Ip Access Policy Manager 15.1.10.7 / 16.1.6+ Fix from $1,9502025-05-07 MEDIUM 5.3 CVE-2025-1695 In NGINX Unit before version 1.34.2 with the Java Language Module in use, undisclosed requests can lead to an infinite loop and cause an increase in … Nginx Unit 1.34.2+ Fix from $1,6002025-03-04 HIGH 7.5 CVE-2025-24326 When BIG-IP Advanced WAF/ASM Behavioral DoS (BADoS) TLS Signatures feature is configured, undisclosed traffic can case an increase in memory resource… Big Ip Application Security Manager 15.1.10.6.0.11.6-ENG / 16.1.5+ Fix from $1,9502025-02-05 HIGH 7.5 CVE-2025-24497 When URL categorization is configured on a virtual server, undisclosed requests can cause TMM to terminate.  Note: Software versions which have reach… Big Ip Policy Enforcement Manager 17.1.2+ Fix from $1,9502025-02-05 HIGH 8.0 CVE-2025-24320 A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run Ja… Big Ip Access Policy Manager 15.1.10.6 / 16.1.5.2+ Fix from $1,9502025-02-05 HIGH 7.5 CVE-2025-24312 When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection profile is configured on a virtual server or firewall rule or policy, … Big Ip Advanced Firewall Manager 1.4.0 / 15.1.10.6.0.11.6+ Fix from $1,9502025-02-05 MEDIUM 6.5 CVE-2025-24319 When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API can cause the BIG-IP Next Central Manager No… Big Ip Next Central Manager 20.3.0+ Fix from $1,6002025-02-05 HIGH 8.7 CVE-2025-23239 When running in Appliance mode, and logged into a highly-privileged role, an authenticated remote command injection vulnerability exists in an undisc… Big Ip Access Policy Manager Mitigation only Fix from $1,9502025-02-05 HIGH 7.5 CVE-2025-22846 When SIP Session and Router ALG profiles are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Managemen… Big Ip Next Service Proxy For Kubernetes 1.7.7 / 15.1.10.6.0.11.6-ENG+ Fix from $1,9502025-02-05 HIGH 7.5 CVE-2025-22891 When BIG-IP PEM Control Plane listener Virtual Server is configured with Diameter Endpoint profile, undisclosed traffic can cause the Virtual Server … Big Ip Policy Enforcement Manager 15.1.10.6.0.11.6 / 16.1.5+ Fix from $1,9502025-02-05 HIGH 7.5 CVE-2025-23412 When BIG-IP APM Access Profile is configured on a virtual server, undisclosed request can cause TMM to terminate. Note: Software versions whic… Big Ip Access Policy Manager 16.1.5 / 17.1.2+ Fix from $1,9502025-02-05 HIGH 7.5 CVE-2025-21087 When Client or Server SSL profiles are configured on a Virtual Server, or DNSSEC signing operations are in use, undisclosed traffic can cause an incr… Big Ip Access Policy Manager 16.1.6 / 17.1.2+ Fix from $1,9502025-02-05 HIGH 7.5 CVE-2025-21091 When SNMP v1 or v2c are disabled on the BIG-IP, undisclosed requests can cause an increase in memory resource utilization. Note: Software versio… Big Ip Access Policy Manager 16.1.6 / 17.1.2+ Fix from $1,9502025-02-05 HIGH 8.8 CVE-2025-20029EPSS 7% Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command, which may allow an authenticated attacker to execu… Big Ip Access Policy Manager 15.1.10.6 / 16.1.5.2+ Fix from $1,9502025-02-05 HIGH 7.5 CVE-2025-20045 When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile are configured on a Message Routi… Big Ip Access Policy Manager 16.1.5 / 17.1.2+ Fix from $1,9502025-02-05 HIGH 7.5 CVE-2025-20058 When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. No… Big Ip Access Policy Manager 16.1.6 / 17.1.2+ Fix from $1,9502025-02-05 MEDIUM 5.4 CVE-2024-10318 A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw … Nginx Api Connectivity Manager 1.9.3 / 2.17.4+ Fix from $1,6002024-11-06 HIGH 7.2 CVE-2024-45844EPSS 11% BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings.  Note: Software v… Big Ip Access Policy Manager 15.1.10.5 / 16.1.5+ Fix from $1,9502024-10-16 MEDIUM 6.8 CVE-2024-47139 A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the … Big Iq Centralized Management Mitigation only Fix from $1,6002024-10-16 HIGH 7.5 CVE-2024-41164 When TCP profile with Multipath TCP enabled (MPTCP) is configured on a Virtual Server, undisclosed traffic along with conditions beyond the attackers… Big Ip Access Policy Manager 16.1.5+ Fix from $1,9502024-08-14 HIGH 7.5 CVE-2024-41727 In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using Intel E810 SR-IOV NIC, undisclosed traffic can ca… Big Ip Access Policy Manager 16.1.5+ Fix from $1,9502024-08-14 MEDIUM 5.5 CVE-2024-41719 When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged in the BIG-IP Centra… Big Ip Next Central Manager 20.2.1+ Fix from $1,6002024-08-14 HIGH 8.8 CVE-2024-39809 The Central Manager user session refresh token does not expire when a user logs out.  Note: Software versions which have reached End of Technical Sup… Big Ip Next Central Manager Mitigation only Fix from $1,9502024-08-14 HIGH 7.5 CVE-2024-39778 When a stateless virtual server is configured on BIG-IP system with a High-Speed Bridge (HSB), undisclosed requests can cause TMM to terminate.   No… Big Ip Access Policy Manager 16.1.5+ Fix from $1,9502024-08-14 HIGH 7.5 CVE-2024-39792 When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests can cause an increase in memory resource utilization.  Note: … Nginx Plus Mitigation only Fix from $1,9502024-08-14 MEDIUM 5.3 CVE-2024-37028 BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in.  Note: Software versions which have reached E… Big Ip Next Central Manager 20.2.1+ Fix from $1,6002024-08-14 MEDIUM 6.5 CVE-2024-32760 When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes t… Nginx Open Source 1.26.1+ Fix from $1,6002024-05-29