Skip to content
Noroxi

F5 records

1,039 published records for vendor f5.

Researcher profile

Entered KEV
14 · 1.3%
Weaponized
22 · 2.1%
Pre-auth RCE
32
With a fix record
19.9%
Median publish → KEV
190 days

All records

1,039 records
  • In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Inte

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    f5 · big-ip access policy managerJul 1, 2020

  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    f5 · big-ip access policy managerMay 5, 2022

  • GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    f5 · big-ip access policy managerMar 31, 2021

  • BIG-IP Configuration utility unauthenticated remote code execution vulnerability

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    f5 · big-ip access policy managerOct 26, 2023

  • A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.

    CriticalCVSS 9.0KEVWeaponizedEPSS 100%

    resf · rocky linuxSep 16, 2021

  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023

  • On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3,

    CriticalCVSS 9.8KEVWeaponizedEPSS 61%

    f5 · big-ip access policy managerMar 31, 2021

  • CVE-2025-53521
    68This week

    BigIP APM Vulnerability

    CriticalCVSS 9.3KEVWeaponizedEPSS 2%

    f5 · big-ip access policy managerOct 15, 2025

  • CVE-2026-94127
    68This week

    BIG-IP APM OAuth vulnerability

    CriticalCVSS 9.3KEVWeaponizedEPSS 2%

    f5 · big-ip access policy managerSep 22, 2026

  • CVE-2023-46748
    66This week

    BIG-IP Configuration utility authenticated SQL injection vulnerability

    HighCVSS 8.8KEVWeaponizedEPSS 4%

    f5 · big-ip access policy managerOct 26, 2023

  • CVE-2009-3555
    65This week

    The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in th

    CriticalCVSS 9.8Proof of conceptEPSS 87%

    apache · http serverNov 9, 2009

  • CVE-2018-14634
    65This week

    An integer overflow flaw was found in the Linux kernel's create_elf_tables() function.

    HighCVSS 7.8KEVWeaponizedEPSS 15%

    linux · linux kernelSep 25, 2018

  • CVE-2022-41622
    63This week

    iControl SOAP vulnerability

    HighCVSS 8.8WeaponizedEPSS 92%

    f5 · big-iq centralized managementDec 7, 2022

  • CVE-2021-22992
    61This week

    On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and

    CriticalCVSS 9.8No exploitEPSS 73%

    f5 · big-ip access policy managerMar 31, 2021

  • CVE-2019-11477
    60This week

    Integer overflow in TCP_SKB_CB(skb)->tcp_gso_segs

    HighCVSS 7.5Proof of conceptEPSS 99%

    linux · linux kernelJun 18, 2019

  • Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc

    HighCVSS 8.1Proof of conceptEPSS 91%

    gnu · glibcFeb 18, 2016

  • The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO

    MediumCVSS 5.5KEVWeaponizedEPSS 22%

    linux · linux kernelMay 7, 2014

  • SACK can cause extensive memory use via fragmented resend queue

    HighCVSS 7.5No exploitEPSS 95%

    linux · linux kernelJun 18, 2019

  • Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes.

    HighCVSS 7.5No exploitEPSS 92%

    linux · linux kernelJun 18, 2019

  • Appliance mode iControl REST vulnerability

    HighCVSS 8.7WeaponizedEPSS 77%

    f5 · big-ip access policy managerDec 7, 2022

  • The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6,

    CriticalCVSS 9.0WeaponizedEPSS 69%

    f5 · big-iq securityDec 7, 2015

  • The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of servi

    HighCVSS 7.5WeaponizedEPSS 87%

    f5 · nginxJul 19, 2013

  • Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service

    HighCVSS 7.5No exploitEPSS 87%

    apple · swiftnioAug 13, 2019