Vulnerability index

Browse CVEs

131 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Big Iq Centralized Management HIGH 8.1
CVE-2026-20916

An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG…

Mitigation only
Fix from $1,950 2026-05-13
Nginx Ingress Controller HIGH 8.3
CVE-2025-14727

A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software versions which have reached En…

Mitigation only
Fix from $1,950 2025-12-17
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-41431

When connection mirroring is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate in …

Mitigation only
Fix from $1,950 2025-05-07
Big Ip Access Policy Manager HIGH 8.7
CVE-2025-23239

When running in Appliance mode, and logged into a highly-privileged role, an authenticated remote command injection vulnerability exists in an undisc…

Mitigation only
Fix from $1,950 2025-02-05
Big Iq Centralized Management MEDIUM 6.8
CVE-2024-47139

A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the …

Mitigation only
Fix from $1,600 2024-10-16
Big Ip Next Central Manager HIGH 8.8
CVE-2024-39809

The Central Manager user session refresh token does not expire when a user logs out.  Note: Software versions which have reached End of Technical Sup…

Mitigation only
Fix from $1,950 2024-08-14
Nginx Plus HIGH 7.5
CVE-2024-39792

When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests can cause an increase in memory resource utilization.  Note: …

Mitigation only
Fix from $1,950 2024-08-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2024-33608

When IPsec is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software …

No fix yet
Fix from $1,950 2024-05-08
Nginx Open Source HIGH 7.5
CVE-2024-24989

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note:…

Mitigation only
Fix from $1,950 2024-02-14
Big Ip Next Service Proxy For Kubernetes HIGH 7.4
CVE-2023-45226

The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacke…

Mitigation only
Fix from $1,950 2023-10-10
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2023-24594

When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization.   N…

Mitigation only
Fix from $1,600 2023-05-03
Njs HIGH 7.5
CVE-2023-27727

Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_function_frame at src/njs_function.h.

No fix yet
Fix from $1,950 2023-04-09
Njs HIGH 7.5
CVE-2022-34032

Nginx NJS v0.7.5 was discovered to contain a segmentation violation in the function njs_value_own_enumerate at src/njs_value.c.

No fix yet
Fix from $1,950 2022-07-18
Njs HIGH 7.5
CVE-2022-34027

Nginx NJS v0.7.4 was discovered to contain a segmentation violation via njs_value_property at njs_value.c.

No fix yet
Fix from $1,950 2022-07-18
Njs HIGH 7.5
CVE-2022-34028

Nginx NJS v0.7.5 was discovered to contain a segmentation violation via njs_utf8_next at src/njs_utf8.h.

No fix yet
Fix from $1,950 2022-07-18
Njs HIGH 7.5
CVE-2022-34030

Nginx NJS v0.7.5 was discovered to contain a segmentation violation via njs_djb_hash at src/njs_djb_hash.c.

No fix yet
Fix from $1,950 2022-07-18
Njs HIGH 7.5
CVE-2022-34031

Nginx NJS v0.7.5 was discovered to contain a segmentation violation via njs_value_to_number at src/njs_value_conversion.h.

No fix yet
Fix from $1,950 2022-07-18
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-29491

On F5 BIG-IP LTM, Advanced WAF, ASM, or APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, an…

Mitigation only
Fix from $1,950 2022-05-05
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2022-29479

On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11…

Mitigation only
Fix from $1,600 2022-05-05
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2022-29480

On F5 BIG-IP 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when multiple route domains are configured, undisclosed requests…

Mitigation only
Fix from $1,600 2022-05-05
Big Ip Access Policy Manager HIGH 7.8
CVE-2022-28714

On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13…

Mitigation only
Fix from $1,950 2022-05-05
Access Policy Manager Clients HIGH 7.8
CVE-2022-29263

On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13…

Mitigation only
Fix from $1,950 2022-05-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-28691

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1…

Mitigation only
Fix from $1,950 2022-05-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-28701

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, when the stream profile is configured on a virtual server, undisclosed requests can cause an increase…

Mitigation only
Fix from $1,950 2022-05-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-28705

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13…

Mitigation only
Fix from $1,950 2022-05-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-28706

On F5 BIG-IP 16.1.x versions prior to 16.1.2 and 15.1.x versions prior to 15.1.5.1, when the DNS resolver configuration is used, undisclosed requests…

Mitigation only
Fix from $1,950 2022-05-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-29473

On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when an IPSec ALG profile is …

Mitigation only
Fix from $1,950 2022-05-05
Big Ip Advanced Firewall Manager HIGH 7.2
CVE-2022-28695

On F5 BIG-IP AFM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior t…

Mitigation only
Fix from $1,950 2022-05-05
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2022-28859

On F5 BIG-IP 15.1.x versions prior to 15.1.5.1 and 14.1.x versions prior to 14.1.4.6, when installing Net HSM, the scripts (nethsm-safenet-install.sh…

Mitigation only
Fix from $1,600 2022-05-05
Big Ip Access Policy Manager MEDIUM 5.9
CVE-2022-28708

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, when a BIG-IP DNS resolver-enabled, HTTP-Explicit or SOCKS prof…

Mitigation only
Fix from $1,600 2022-05-05