Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.9F5

Medium [CVE-2025-58153] Under undisclosed traffic conditions along with conditions beyond the attacker's control, hardware systems with a High-Speed…

Under undisclosed traffic conditions along with conditions beyond the attacker's control, hardware systems with a High-Speed Bridge (HSB) may experience a lockup of the HSB. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-58153
Unclassified
Oct 15, 2025
Medium6.5F5

Medium [CVE-2025-55670] On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls

On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-55670
BIG-IPBIG-IP Next
Oct 15, 2025
Medium6.5F5

Medium [CVE-2025-54805] When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process

When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can cause an increase in the Traffic Management Microkernel (TMM) memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-54805
Unclassified
Oct 15, 2025
Medium4.9F5

Medium [CVE-2025-54755] directory traversal vulnerability exists in TMUI that allows a highly privileged authenticated attacker to access files

A directory traversal vulnerability exists in TMUI that allows a highly privileged authenticated attacker to access files which are not limited to the intended files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-54755
Unclassified
Oct 15, 2025
Medium6.5F5

Medium [CVE-2025-47150] When SNMP is configured on F5OS Appliance and Chassis systems, undisclosed requests

When SNMP is configured on F5OS Appliance and Chassis systems, undisclosed requests can cause an increase in SNMP memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-47150
F5OS / Distributed Cloud
Oct 15, 2025
Medium6.5F5

Medium [CVE-2025-47148] When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity…

When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) enabled on an access policy, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-47148
BIG-IP
Oct 15, 2025
High7.4F5

High [CVE-2025-54809] F5 Access for Android before version 3.1.2 which uses HTTPS does not verify the remote endpoint identity.

F5 Access for Android before version 3.1.2 which uses HTTPS does not verify the remote endpoint identity. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-54809
Unclassified
Aug 13, 2025
High7.5F5

High [CVE-2025-52585] When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous…

When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diffie-Hellman (ADH) ciphers enabled, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-52585
BIG-IP
Aug 13, 2025
High7.3F5

High [CVE-2025-48500] missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may

A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, authenticated attacker with access to the local file system to replace it with a malicious package installer. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-48500
Unclassified
Aug 13, 2025
High7.5F5

High [CVE-2025-46405] When Network Access is configured on a BIG-IP APM virtual server, undisclosed traffic

When Network Access is configured on a BIG-IP APM virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-46405
BIG-IP
Aug 13, 2025
Medium5.3F5

Medium [CVE-2025-54500] HTTP/2 implementation flaw

An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-54500
Unclassified
Aug 13, 2025
Low3.7F5

Low [CVE-2025-53859] NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP authentication process memory; as a result, the server side may leak arbitrary bytes sent in a request to the authentication server. This issue happens during the NGINX SMTP authentication process and requires the attacker to make preparations against the target system to extract the leaked data. The issue affects NGINX only if (1) it is built with the ngx_mail_smtp_module, (2) the smtp_auth directive is configured with method "none," and (3) the authentication server returns the "Auth-Wait" response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-53859
NGINX
Aug 13, 2025
High8.8F5

High [CVE-2025-46265] On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+)

On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may be authorized with higher privilege F5OS roles. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-46265
F5OS / Distributed Cloud
May 7, 2025
High7.5F5

High [CVE-2025-41433] When a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured…

When a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured on a Message Routing virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-41433
Unclassified
May 7, 2025
High7.5F5

High [CVE-2025-41431] BIG-IP: When connection mirroring is configured on a virtual server, undisclosed requests

When connection mirroring is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate in the standby BIG-IP systems in a traffic group. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-41431
BIG-IP
May 7, 2025
High7.5F5

High [CVE-2025-41414] When HTTP/2 client and server profile is configured on a virtual server, undisclosed requests can cause TMM to terminate

When HTTP/2 client and server profile is configured on a virtual server, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2025-41414
Unclassified
May 7, 2025
High7.5F5

High [CVE-2025-41399] When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests

When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-41399
Unclassified
May 7, 2025
High7.5F5

High [CVE-2025-36557] When an HTTP profile with the Enforce RFC Compliance option is configured on a virtual server, undisclosed requests

When an HTTP profile with the Enforce RFC Compliance option is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-36557
Unclassified
May 7, 2025
High8.1F5

High [CVE-2025-36546] On an F5OS system, if the root user had previously configured the system to allow login

On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication, and then enabled Appliance Mode; access via SSH key-based authentication is still allowed. For an attacker to exploit this vulnerability they must obtain the root user's SSH private key. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-36546
F5OS / Distributed Cloud
May 7, 2025
High7.5F5

High [CVE-2025-36525] When a BIG-IP APM virtual server is configured to use a PingAccess profile, undisclosed requests can cause TMM to terminate

When a BIG-IP APM virtual server is configured to use a PingAccess profile, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-36525
BIG-IP
May 7, 2025