F5
904 known vulnerabilities
Top Products
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof thei
When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blo
When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (
When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to ter
When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) comm
When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the
A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with
When a BIG-IP is configured with DNS caching (Such as a DNS profile with caching enabled, SSL Orchestrator, Advanced WA
When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication,
An authenticated iControl SOAP user may be able to obtain information of other accounts. Note: Software versions which
When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iContro
When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic
A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administra
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the
When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return t
When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that
An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iCon
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker t
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling o
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of
The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to
When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause
A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secr
When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with con
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error mes
A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attackers to gain access
A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) s
Frequently Asked Questions
How many CVEs affect F5?
F5 has 904 CVE records in our database, including 20 critical and 477 high severity vulnerabilities.
What are the most severe F5 vulnerabilities?
F5 has 20 critical severity (CVSS 9.0+) and 477 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for F5 vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in F5 products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect F5 Vulnerabilities
CyberStrike scans your infrastructure for F5 vulnerabilities and provides real-time remediation guidance.
Get Started