F5
904 known vulnerabilities
Top Products
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and
When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filte
The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files ou
When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist wh
When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection
When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with per
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string express
When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerabilit
When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or p
NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules.
When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists w
NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled
A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists w
Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and i
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charse
When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Applia
When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set
An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects th
When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic ca
A vulnerability exists in BIG-IP systems that may allow an authenticated attacker with administrative access to escalate
When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cau
A directory traversal vulnerability exists in BIG-IP SSL Orchestrator that allows an authenticated attacker with high pr
When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a virtual s
When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command that may allow a high
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the
A vulnerability exists in iControl SOAP where an authenticated attacker with the Resource Administrator or Administrator
An authenticated attacker's undisclosed requests to BIG-IP iControl REST can lead to an information leak of BIG-IP local
Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics command
An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configu
When a classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Manageme
Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) co
A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Ad
On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in mem
A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role
An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read
When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIF
A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with
A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility. Note: So
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client direc
A vulnerability exists in the undisclosed pages in the Configuration utility that may allow a low-privileged authenticat
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the
An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through
When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processin
When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technolog
Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command which m
Frequently Asked Questions
How many CVEs affect F5?
F5 has 904 CVE records in our database, including 20 critical and 477 high severity vulnerabilities.
What are the most severe F5 vulnerabilities?
F5 has 20 critical severity (CVSS 9.0+) and 477 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for F5 vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in F5 products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect F5 Vulnerabilities
CyberStrike scans your infrastructure for F5 vulnerabilities and provides real-time remediation guidance.
Get Started