Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.3
CVE-2024-34161
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) o…
Nginx Open Source
1.26.1+
MEDIUM 5.3
CVE-2024-35200
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate.
Nginx Open Source
1.26.1+
MEDIUM 6.8
CVE-2024-33612
An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider …
Big Ip Next Central Manager
20.2.0+
HIGH 7.5
CVE-2024-33608
When IPsec is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.
Note: Software …
Big Ip Access Policy Manager
No fix yet
MEDIUM 6.5
CVE-2024-32761
Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running on VELOS and rSeries platform…
Big Ip Access Policy Manager
15.1.10+
MEDIUM 6.1
CVE-2024-33604
A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that allows an attacker to run Jav…
Big Ip Access Policy Manager
15.1.10.4 / 16.1.4.3+
HIGH 8.0
CVE-2024-31156
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run Ja…
Big Ip Access Policy Manager
15.1.10.4 / 16.1.4.3+
HIGH 7.4
CVE-2024-28883
An origin validation vulnerability exists in
BIG-IP APM browser network access VPN client
for Windows, macOS and Linux which may allow an atta…
Big Ip Access Policy Manager
7.2.4.4 / 15.1.10.3+
HIGH 7.4
CVE-2024-32049
BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials.
Note: Softwa…
Big Ip Next Central Manager
20.1.0+
MEDIUM 5.9
CVE-2024-28889
When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffic along with conditions beyond t…
Big Ip Access Policy Manager
15.1.10.4 / 16.1.4.3+
HIGH 7.5
CVE-2024-25560
When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate.
Note: Soft…
Big Ip Access Policy Manager
15.1.10.8 / 16.1.4+
HIGH 7.5
CVE-2024-26026EPSS 7%
An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Supp…
Big Ip Next Central Manager
20.2.0+
HIGH 7.5
CVE-2024-21793EPSS 7%
An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Su…
Big Ip Next Central Manager
20.2.0+
HIGH 7.5
CVE-2024-24989
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate.
Note:…
Nginx Open Source
Mitigation only
HIGH 7.5
CVE-2024-24990
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate.
Note:…
Nginx Open Source
1.25.4+
MEDIUM 5.5
CVE-2024-24966
When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly authorized. Note: Software version…
F5os A
1.6.0+
HIGH 7.5
CVE-2024-23805
Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Application Visibility and Reporting module, this may o…
Big Ip Advanced Web Application Firewall
15.1.10 / 16.1.4+
HIGH 7.5
CVE-2024-23979
When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, …
Big Ip Access Policy Manager
15.1.9 / 16.1.4+
HIGH 7.5
CVE-2024-23982
When a BIG-IP PEM classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TM…
Big Ip Policy Enforcement Manager
after 17.1.1
HIGH 7.5
CVE-2024-24775
When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (T…
Big Ip Access Policy Manager
15.1.9 / 16.1.4+
MEDIUM 6.0
CVE-2024-23976
When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance
mode restrictions utilizing…
Big Ip Access Policy Manager
15.1.9 / 16.1.4+
HIGH 7.5
CVE-2024-23308
When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, undisclosed requests can cause t…
Big Ip Advanced Web Application Firewall
17.1.1+
HIGH 7.5
CVE-2024-23314
When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate…
Big Ip Access Policy Manager
15.1.9 / 16.1.4+
HIGH 7.1
CVE-2024-23306
A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files. Note: Software versions which have r…
Big Ip Next Cloud Native Network Functions
1.2.0+
MEDIUM 5.5
CVE-2024-23607
A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read files outside the QKView director…
F5os A
1.4.0 / 1.6.0+
HIGH 8.7
CVE-2024-22093
When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-blad…
Big Ip Access Policy Manager
15.1.9 / 16.1.4+
HIGH 7.5
CVE-2024-21789
When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utili…
Big Ip Advanced Web Application Firewall
17.1.1+
HIGH 7.5
CVE-2024-21849
When an Advanced WAF/ASM security policy and a Websockets profile are configured on a virtual server, undisclosed traffic can cause the Traffic Manag…
Big Ip Advanced Web Application Firewall
16.1.4+
HIGH 7.2
CVE-2024-22389
When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device.
Note: S…
Big Ip Access Policy Manager
15.1.9 / 16.1.4+
MEDIUM 6.7
CVE-2024-21782
BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced…
Big Ip Access Policy Manager
15.1.9 / 16.1.4+