f5

1,024 tracked vulnerabilities.

CVE-2021-23020 MEDIUM
F5 NGINX Controller 3.0.0-3.9.9 - Use of Insufficiently Random Values in API Key Generation
Jun 01, 2021
CVSS 5.5
EPSS 0.00
CVE-2021-23019 HIGH
NGINX Controller <3.15.0 - Info Disclosure
Jun 01, 2021
CVSS 7.8
EPSS 0.00
CVE-2021-23017 HIGH
nginx 0.6.18-1.20.0 - Denial of Service via DNS Resolver Off-by-one Error
Jun 01, 2021
CVSS 7.7
EPSS 0.74
CVE-2021-23018 HIGH
NGINX Controller <3.4.0 - Info Disclosure
Jun 01, 2021
CVSS 7.4
EPSS 0.00
CVE-2021-23016 MEDIUM
BIG-IP APM <16.0.x, 12.1.x, 11.6.x - Auth Bypass
May 10, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-23015 HIGH
F5 BIG-IP 13.1.0-13.1.3.6, 14.1.0-14.1.4.1, 15.1.0-15.1.2.1, 16.0.x - Auth Bypass via iControl REST
May 10, 2021
CVSS 7.2
EPSS 0.00
CVE-2021-23014 HIGH
BIG-IP <16.0.1.1, <15.1.3, <14.1.4 - Auth Bypass
May 10, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-23012 HIGH
BIG-IP 13.1.0-13.1.3, 14.1.0-14.1.3, 15.1.0-15.1.2, 16.0.0-16.0.1 - OS Command Injection via System Support
May 10, 2021
CVSS 8.2
EPSS 0.00
CVE-2021-23010 HIGH
BIG-IP ASM/Advanced WAF <16.0.1.1, 15.1.2, 14.1.3.1, 13.1.3.5, 12.1...
May 10, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-23009 HIGH
BIG-IP 15.1.0-15.1.2 - Denial of Service via Malformed HTTP/2 Request
May 10, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-23013 HIGH
BIG-IP <16.0.1.1, 15.1.x <15.1.3, 14.1.x <14.1.4, 13.1.x <13.1.3.6,...
May 10, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-23011 HIGH
BIG-IP <16.0.1.1, 15.1.3, 14.1.4, 13.1.4, 12.1.6, 11.6.5.3 - DoS
May 10, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-23008 CRITICAL
BIG-IP APM <15.1.3,14.1.4,13.1.4,12.1.6,16.0.x,11.6.x - Auth Bypass
May 10, 2021
CVSS 9.8
EPSS 0.01
CVE-2021-23007 MEDIUM
BIG-IP 14.1.4 and 16.0.1.1 - Denial of Service via Fragmented IP Traffic Handling
Mar 31, 2021
CVSS 5.3
EPSS 0.01
CVE-2021-23006 MEDIUM
F5 BIG-IQ Centralized Management 6.0.0-7.x - Reflected Cross-Site Scripting
Mar 31, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-23005 CRITICAL
F5 BIG-IQ Centralized Management 6.x-7.x - Unencrypted Corosync Protocol Usage in Quorum Device HA
Mar 31, 2021
CVSS 9.1
EPSS 0.00
CVE-2021-23004 HIGH
BIG-IP <16.0.1.1, 15.1.x <15.1.2, 14.1.x <14.1.3.1, 13.1.x <13.1.3....
Mar 31, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-23003 HIGH
BIG-IP <16.0.1.1, 15.1.x <15.1.2, 14.1.x <14.1.3.1, 13.1.x <13.1.3....
Mar 31, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-23002 MEDIUM
BIG-IP APM <16.0.1.1, <15.1.2.1, <14.1.4, <13.1.3.6, <=12.1.x, <=11...
Mar 31, 2021
CVSS 4.5
EPSS 0.00
CVE-2021-23001 MEDIUM
BIG-IP Advanced WAF and ASM 11.6.1-11.6.5.2 - Authenticated Unrestricted File Upload via iControl REST Endpoint
Mar 31, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-23000 HIGH
F5 BIG-IP 13.1.3.4-13.1.3.6 - Denial of Service via Malicious HTTP Request Sequence
Mar 31, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-22999 HIGH
F5 BIG-IP 14.1.0-14.1.3 - Denial of Service via HTTP/2 to HTTP/1.x Connection Handling
Mar 31, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-22998 MEDIUM
BIG-IP <16.0.1.1, 15.1.2.1, 14.1.4, 13.1.3.6, 12.1.5.3, 11.6.5.3 - DoS
Mar 31, 2021
CVSS 5.3
EPSS 0.01
CVE-2021-22997 HIGH
F5 BIG-IQ Centralized Management 6.0.0-7.x - Unauthenticated ElasticSearch Transport Service Access
Mar 31, 2021
CVSS 7.5
EPSS 0.00
CVE-2021-22996 HIGH
F5 BIG-IQ Centralized Management 7.x < 8.0.0 - Denial of Service via Corosync Process Abort
Mar 31, 2021
CVSS 7.5
EPSS 0.01