F5 records
1,039 published records for vendor f5.
Researcher profile
- Entered KEV
- 14 · 1.3%
- Weaponized
- 22 · 2.1%
- Pre-auth RCE
- 32
- With a fix record
- 19.9%
- Median publish → KEV
- 190 days
Recurring classes
- CWE-20 Improper Input Validation79
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')75
- CWE-400 Uncontrolled Resource Consumption57
- CWE-476 NULL Pointer Dereference34
- CWE-125 Out-of-bounds Read31
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor27
The weakness classes this vendor ships most often: where to look.
CWEAll records
1,039 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2020-5902Weaponized | In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Intef5 · big-ip access policy manager · CWE-22 | Critical9.8 | KEV | 100.0% | Jul 1, 2020 |
99Now | CVE-2014-6271Weaponized | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Critical9.8 | KEV | 100.0% | Sep 24, 2014 |
99Now | CVE-2022-1388Weaponized | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior f5 · big-ip access policy manager · CWE-306 | Critical9.8 | KEV | 100.0% | May 5, 2022 |
99Now | CVE-2014-7169Weaponized | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Critical9.8 | KEV | 99.9% | Sep 24, 2014 |
99Now | CVE-2021-22986Weaponized | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 f5 · big-ip access policy manager · CWE-918 | Critical9.8 | KEV | 99.9% | Mar 31, 2021 |
98Now | CVE-2023-46747Weaponized | BIG-IP Configuration utility unauthenticated remote code execution vulnerabilityf5 · big-ip access policy manager · CWE-288 | Critical9.8 | KEV | 96.5% | Oct 26, 2023 |
96Now | CVE-2021-40438Weaponized | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.resf · rocky linux · CWE-918 | Critical9.0 | KEV | 100.0% | Sep 16, 2021 |
90Now | CVE-2023-44487Weaponized | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | High7.5 | KEV | 100.0% | Oct 10, 2023 |
87Now | CVE-2021-22991Weaponized | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3,f5 · big-ip access policy manager · CWE-119 | Critical9.8 | KEV | 61.1% | Mar 31, 2021 |
68This week | CVE-2025-53521Weaponized | BigIP APM Vulnerabilityf5 · big-ip access policy manager · CWE-121 | Critical9.3 | KEV | 2.3% | Oct 15, 2025 |
68This week | CVE-2026-94127Weaponized | BIG-IP APM OAuth vulnerabilityf5 · big-ip access policy manager · CWE-122 | Critical9.3 | KEV | 2.2% | Sep 22, 2026 |
66This week | CVE-2023-46748Weaponized | BIG-IP Configuration utility authenticated SQL injection vulnerabilityf5 · big-ip access policy manager · CWE-89 | High8.8 | KEV | 4.5% | Oct 26, 2023 |
65This week | CVE-2009-3555Proof of concept | The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in thapache · http server · CWE-295 | Critical9.8 | — | 87.3% | Nov 9, 2009 |
65This week | CVE-2018-14634Weaponized | An integer overflow flaw was found in the Linux kernel's create_elf_tables() function.linux · linux kernel · CWE-190 | High7.8 | KEV | 14.7% | Sep 25, 2018 |
63This week | CVE-2022-41622Weaponized | iControl SOAP vulnerabilityf5 · big-iq centralized management · CWE-352 | High8.8 | — | 92.4% | Dec 7, 2022 |
61This week | CVE-2021-22992No exploit | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, andf5 · big-ip access policy manager · CWE-120 | Critical9.8 | — | 72.7% | Mar 31, 2021 |
60This week | CVE-2019-11477Proof of concept | Integer overflow in TCP_SKB_CB(skb)->tcp_gso_segslinux · linux kernel · CWE-190 | High7.5 | — | 98.7% | Jun 18, 2019 |
59Plan | CVE-2015-7547Proof of concept | Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc gnu · glibc · CWE-119 | High8.1 | — | 91.0% | Feb 18, 2016 |
59Plan | CVE-2014-0196Weaponized | The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO linux · linux kernel · CWE-362 | Medium5.5 | KEV | 22.5% | May 7, 2014 |
58Plan | CVE-2019-11478No exploit | SACK can cause extensive memory use via fragmented resend queuelinux · linux kernel · CWE-770 | High7.5 | — | 94.7% | Jun 18, 2019 |
57Plan | CVE-2019-11479No exploit | Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes.linux · linux kernel · CWE-405 | High7.5 | — | 91.7% | Jun 18, 2019 |
57Plan | CVE-2022-41800Weaponized | Appliance mode iControl REST vulnerabilityf5 · big-ip access policy manager · CWE-77 | High8.7 | — | 76.9% | Dec 7, 2022 |
57Plan | CVE-2015-3628Weaponized | The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6,f5 · big-iq security · CWE-264 | Critical9.0 | — | 69.3% | Dec 7, 2015 |
56Plan | CVE-2013-2028Weaponized | The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of servif5 · nginx · CWE-787 | High7.5 | — | 87.5% | Jul 19, 2013 |
56Plan | CVE-2019-9515No exploit | Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | High7.5 | — | 87.4% | Aug 13, 2019 |
- CVE-2020-590299Now
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Inte
CriticalCVSS 9.8KEVWeaponizedEPSS 100%f5 · big-ip access policy managerJul 1, 2020
- CVE-2014-627199Now
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2022-138899Now
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior
CriticalCVSS 9.8KEVWeaponizedEPSS 100%f5 · big-ip access policy managerMay 5, 2022
- CVE-2014-716999Now
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2021-2298699Now
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3
CriticalCVSS 9.8KEVWeaponizedEPSS 100%f5 · big-ip access policy managerMar 31, 2021
- CVE-2023-4674798Now
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 97%f5 · big-ip access policy managerOct 26, 2023
- CVE-2021-4043896Now
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
CriticalCVSS 9.0KEVWeaponizedEPSS 100%resf · rocky linuxSep 16, 2021
- CVE-2023-4448790Now
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
HighCVSS 7.5KEVWeaponizedEPSS 100%siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023
- CVE-2021-2299187Now
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3,
CriticalCVSS 9.8KEVWeaponizedEPSS 61%f5 · big-ip access policy managerMar 31, 2021
- CVE-2025-5352168This week
BigIP APM Vulnerability
CriticalCVSS 9.3KEVWeaponizedEPSS 2%f5 · big-ip access policy managerOct 15, 2025
- CVE-2026-9412768This week
BIG-IP APM OAuth vulnerability
CriticalCVSS 9.3KEVWeaponizedEPSS 2%f5 · big-ip access policy managerSep 22, 2026
- CVE-2023-4674866This week
BIG-IP Configuration utility authenticated SQL injection vulnerability
HighCVSS 8.8KEVWeaponizedEPSS 4%f5 · big-ip access policy managerOct 26, 2023
- CVE-2009-355565This week
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in th
CriticalCVSS 9.8Proof of conceptEPSS 87%apache · http serverNov 9, 2009
- CVE-2018-1463465This week
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function.
HighCVSS 7.8KEVWeaponizedEPSS 15%linux · linux kernelSep 25, 2018
- CVE-2022-4162263This week
iControl SOAP vulnerability
HighCVSS 8.8WeaponizedEPSS 92%f5 · big-iq centralized managementDec 7, 2022
- CVE-2021-2299261This week
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and
CriticalCVSS 9.8No exploitEPSS 73%f5 · big-ip access policy managerMar 31, 2021
- CVE-2019-1147760This week
Integer overflow in TCP_SKB_CB(skb)->tcp_gso_segs
HighCVSS 7.5Proof of conceptEPSS 99%linux · linux kernelJun 18, 2019
- CVE-2015-754759Plan
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc
HighCVSS 8.1Proof of conceptEPSS 91%gnu · glibcFeb 18, 2016
- CVE-2014-019659Plan
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO
MediumCVSS 5.5KEVWeaponizedEPSS 22%linux · linux kernelMay 7, 2014
- CVE-2019-1147858Plan
SACK can cause extensive memory use via fragmented resend queue
HighCVSS 7.5No exploitEPSS 95%linux · linux kernelJun 18, 2019
- CVE-2019-1147957Plan
Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes.
HighCVSS 7.5No exploitEPSS 92%linux · linux kernelJun 18, 2019
- CVE-2022-4180057Plan
Appliance mode iControl REST vulnerability
HighCVSS 8.7WeaponizedEPSS 77%f5 · big-ip access policy managerDec 7, 2022
- CVE-2015-362857Plan
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6,
CriticalCVSS 9.0WeaponizedEPSS 69%f5 · big-iq securityDec 7, 2015
- CVE-2013-202856Plan
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of servi
HighCVSS 7.5WeaponizedEPSS 87%f5 · nginxJul 19, 2013
- CVE-2019-951556Plan
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service
HighCVSS 7.5No exploitEPSS 87%apple · swiftnioAug 13, 2019