Skip to main content

Vendor archive

f5 CVEs

Beta · best-effort

1,024 CVEs tagged to vendor f575 Critical, 562 High, 372 Medium, 15 Low, 0 Unrated.

CVE-2025-61933

Published Oct 15, 2025

A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM that allows an attacker to run JavaScript in the context of the targeted logged-ou…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-57780

Published Oct 15, 2025

A vulnerability exists in F5OS-A and F5OS-C system that may allow an authenticated attacker with local access to escalate their privileges.  A successful exploit may allow the att…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-53860

Published Oct 15, 2025

A vulnerability exists in F5OS-A software that allows a highly privileged authenticated attacker to access sensitive FIPS hardware security module (HSM) information on F5 rSeries…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-61960

Published Oct 15, 2025

When a per-request policy is configured on a BIG-IP APM portal access virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: S…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-61955

Published Oct 15, 2025

A vulnerability exists in F5OS-A and F5OS-C systems that may allow an authenticated attacker with local access to escalate their privileges.  A successful exploit may allow the at…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-60015

Published Oct 15, 2025

An out-of-bounds write vulnerability exists in F5OS-A and F5OS-C that could lead to memory corruption.  Note: Software versions which have reached End of Technical Support (E…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-60013

Published Oct 15, 2025

When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with special shell metacharacters, arbitrary system commands may b…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59778

Published Oct 15, 2025

When the Allowed IP Addresses feature is configured on the F5OS-C partition control plane, undisclosed traffic can cause multiple containers to terminate.   Note: Software versio…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59478

Published Oct 15, 2025

When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort
Showing 76-100 of 1,024 CVEsPage 4 of 41