f5

1,024 tracked vulnerabilities.

CVE-2025-54479 HIGH
F5 BIG-IP Next Cloud-Native Network Functions 1.1.0-1.3.9 - Denial of Service via Classification Profile Configuration
Oct 15, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-53868 HIGH
F5 BIG-IP 15.1.0-15.1.10.8 - Authenticated Appliance Mode Restriction Bypass via SCP/SFTP Commands
Oct 15, 2025
CVSS 8.7
EPSS 0.00
CVE-2025-53856 HIGH
F5 BIG-IP 15.1.0-15.1.10.8 - Denial of Service via ePVA Traffic Handling
Oct 15, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-53521 CRITICAL KEV
F5 BIG-IP Access Policy Manager 15.1.0-15.1.10.8 - Remote Code Execution via Malicious Traffic
Oct 15, 2025
CVSS 9.8
EPSS 0.07
CVE-2025-53474 HIGH
F5 BIG-IP ILX::call - TMM Denial of Service
Oct 15, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-48008 HIGH
F5 BIG-IP - Denial of Service via MPTCP Traffic Handling
Oct 15, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-47150 MEDIUM
F5OS-A 1.5.1-1.5.3 and F5OS-C 1.6.0-1.6.4 - Memory Leak via SNMP Requests
Oct 15, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-47148 MEDIUM
F5 BIG-IP APM/SSL Orchestrator 15.1.0-15.1.10.8 Memory Exhaustion via SAML SLO
Oct 15, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-46706 HIGH
F5 F5 BIG-IP 16.1.0 through 16.1.6 - Memory Resource Exhaustion via iRule HTTP::respond
Oct 15, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-41430 HIGH
F5 BIG-IP SSL Orchestrator >=15.1.0 <15.1.9 - Denial of Service via Traffic Management Microkernel Termination
Oct 15, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-54809 HIGH
F5 Access for Android 3.1.0-3.1.1 - Improper Certificate Validation
Aug 13, 2025
CVSS 7.4
EPSS 0.00
CVE-2025-54500 MEDIUM
F5 BIG-IP 15.1.0-15.1.10.8 - Denial of Service via HTTP/2 Control Frame Manipulation
Aug 13, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-53859 LOW
NGINX Open Source >=0.7.22 <1.29.1 and NGINX Plus - Unauthenticated Out-of-bounds Read in SMTP Authentication Process
Aug 13, 2025
CVSS 3.7
EPSS 0.00
CVE-2025-52585 HIGH
BIG-IP 15.1.0-15.1.10.8 - Denial of Service via SSL Forward Proxy with ADH Ciphers
Aug 13, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-48500 HIGH
MacOS F5 VPN < - Local Privilege Escalation
Aug 13, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-46405 HIGH
BIG-IP Access Policy Manager 15.1.0-15.1.10.8 - Denial of Service via Network Access Traffic
Aug 13, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-46265 HIGH
F5OS-A and F5OS-C >=1.6.0 <1.6.2 - Authenticated Incorrect Authorization
May 07, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-43878 MEDIUM
F5OS-A 1.5.1-1.8.0 and F5OS-C 1.6.0-1.6.2 - Authenticated Appliance Mode Restriction Bypass via tcpdump Utility
May 07, 2025
CVSS 6.0
EPSS 0.00
CVE-2025-41433 HIGH
F5 BIG-IP 15.1.0-15.1.10 - Denial of Service via SIP MRF ALG Profile
May 07, 2025
CVSS 7.5
EPSS 0.01
CVE-2025-41431 HIGH
BIG-IP - Out-of-bounds Write via Connection Mirroring
May 07, 2025
CVSS 7.5
EPSS 0.01
CVE-2025-41414 HIGH
F5 BIG-IP 15.1.0-15.1.9 - Denial of Service via HTTP/2 Profile
May 07, 2025
CVSS 7.5
EPSS 0.01
CVE-2025-41399 HIGH
F5 BIG-IP 15.1.0-15.1.8 - Memory Resource Exhaustion via SCTP Profile
May 07, 2025
CVSS 7.5
EPSS 0.01
CVE-2025-36557 HIGH
F5 BIG-IP 16.1.0-16.1.4 - Denial of Service via HTTP Profile RFC Compliance Enforcement
May 07, 2025
CVSS 7.5
EPSS 0.01
CVE-2025-36546 HIGH
F5OS-A 1.5.1-1.5.3 and F5OS-C 1.6.0-1.6.2 - Incorrect Authorization via SSH Key-Based Authentication
May 07, 2025
CVSS 8.1
EPSS 0.00
CVE-2025-36525 HIGH
F5 BIG-IP Access Policy Manager 15.1.0-15.1.10.7.0.4.5 - Denial of Service via PingAccess Profile
May 07, 2025
CVSS 7.5
EPSS 0.01