CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-60016
7.5 HIGH

When Diffie-Hellman (DH) group Elliptic Curve Cryptography (ECC) Brainpool curves are configured in an SSL profile's Cipher Rule or Cipher Group, and that profile is …

Oct 15, 2025
CVE-2025-60015
5.7 MEDIUM

An out-of-bounds write vulnerability exists in F5OS-A and F5OS-C that could lead to memory corruption. Note: Software versions which have reached End of Technical Support …

Oct 15, 2025
CVE-2025-60013
4.6 MEDIUM

When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with special shell metacharacters, arbitrary system commands may be executed, …

Oct 15, 2025
CVE-2025-59781
7.5 HIGH

When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undisclosed DNS queries can cause an increase in memory resource utilization. …

Oct 15, 2025
CVE-2025-59778
7.5 HIGH

When the Allowed IP Addresses feature is configured on the F5OS-C partition control plane, undisclosed traffic can cause multiple containers to terminate. Note: Software versions …

Oct 15, 2025
CVE-2025-59483
6.5 MEDIUM

A validation vulnerability exists in an undisclosed URL in the Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not …

Oct 15, 2025
CVE-2025-59481
8.7 HIGH

A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with at least resource administrator …

Oct 15, 2025
CVE-2025-59478
7.5 HIGH

When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to …

Oct 15, 2025
CVE-2025-59269
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the …

Oct 15, 2025
CVE-2025-59268
5.3 MEDIUM

On the BIG-IP system, undisclosed endpoints that contain static non-sensitive information are accessible to an unauthenticated remote attacker through the Configuration utility. Note: Software versions …

Oct 15, 2025
CVE-2025-58474
5.3 MEDIUM

When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or when an NGINX server is configured with App …

Oct 15, 2025
CVE-2025-58424
5.3 MEDIUM

On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols which do not have message integrity protection. Note: Software versions …

Oct 15, 2025
CVE-2025-58153
5.9 MEDIUM

Under undisclosed traffic conditions along with conditions beyond the attacker's control, hardware systems with a High-Speed Bridge (HSB) may experience a lockup of the HSB. …

Oct 15, 2025
CVE-2025-58120
7.5 HIGH

When HTTP/2 Ingress is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical …

Oct 15, 2025
CVE-2025-58096
7.5 HIGH

When the database variable tm.tcpudptxchecksum is configured as non-default value Software-only on a BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to …

Oct 15, 2025
CVE-2025-56746
2.2 LOW

Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user …

Oct 15, 2025
CVE-2025-55670
6.5 MEDIUM

On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microkernel (TMM) to …

Oct 15, 2025
CVE-2025-55669
7.5 HIGH

When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured on a virtual server, undisclosed traffic can cause the …

Oct 15, 2025
CVE-2025-55036
7.5 HIGH

When BIG-IP SSL Orchestrator explicit forward proxy is configured on a virtual server and the proxy connect feature is enabled, undisclosed traffic may cause memory …

Oct 15, 2025
CVE-2025-54858
7.5 HIGH

When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed JSON schema, and the …

Oct 15, 2025
CVE-2025-54854
7.5 HIGH

When a BIG-IP APM OAuth access profile (Resource Server or Resource Client) is configured on a virtual server, undisclosed traffic can cause the apmd process …

Oct 15, 2025
CVE-2025-54805
6.5 MEDIUM

When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can cause an increase in the Traffic …

Oct 15, 2025
CVE-2025-54755
4.9 MEDIUM

A directory traversal vulnerability exists in TMUI that allows a highly privileged authenticated attacker to access files which are not limited to the intended files. …

Oct 15, 2025
CVE-2025-54479
7.5 HIGH

When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, undisclosed requests can cause the Traffic Management Microkernel (TMM) …

Oct 15, 2025
CVE-2025-53868
8.7 HIGH

When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to bypass Appliance mode restrictions using …

Oct 15, 2025
CVE-2025-53856
7.5 HIGH

When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object uses the embedded Packet Velocity Acceleration (ePVA) feature, undisclosed …

Oct 15, 2025
CVE-2025-53521
9.8 CRITICAL KEV

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions …

Oct 15, 2025
CVE-2025-53474
7.5 HIGH

When an iRule using an ILX::call command is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: …

Oct 15, 2025
CVE-2025-48008
7.5 HIGH

When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can …

Oct 15, 2025
CVE-2025-47150
6.5 MEDIUM

When SNMP is configured on F5OS Appliance and Chassis systems, undisclosed requests can cause an increase in SNMP memory resource utilization. Note: Software versions which …

Oct 15, 2025
CVE-2025-47148
6.5 MEDIUM

When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) …

Oct 15, 2025
CVE-2025-46706
7.5 HIGH

When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software …

Oct 15, 2025
CVE-2025-41430
7.5 HIGH

When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of …

Oct 15, 2025
CVE-2025-9640
4.3 MEDIUM

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated …

Oct 15, 2025
CVE-2025-10869
6.1 MEDIUM

Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by injecting a malicious …

Oct 15, 2025
CVE-2025-55082
5.3 MEDIUM

In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was a potential out of bound read in _nx_secure_tls_process_clienthello() because of a …

Oct 15, 2025
CVE-2025-55081
9.1 CRITICAL

In Eclipse Foundation NextX Duo before 6.4.4, a module of ThreadX, the _nx_secure_tls_process_clienthello() function was missing length verification of certain SSL/TLS client hello message: the …

Oct 15, 2025
CVE-2025-9967
9.8 CRITICAL

The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.7. This …

Oct 15, 2025
CVE-2025-11728
5.3 MEDIUM

The Oceanpayment CreditCard Gateway plugin for WordPress is vulnerable to unauthenticated and unauthorized modification of data due to missing authentication and capability checks on the …

Oct 15, 2025
CVE-2025-11722
7.5 HIGH

The Woocommerce Category and Products Accordion Panel plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0 via …

Oct 15, 2025
CVE-2025-11701
5.3 MEDIUM

The Zip Attachments plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check as well as missing post status …

Oct 15, 2025
CVE-2025-11692
5.3 MEDIUM

The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and capability checks on the download.php file …

Oct 15, 2025
CVE-2025-11365
6.5 MEDIUM

The WP Google Map Plugin plugin for WordPress is vulnerable to blind SQL Injection via the 'id' parameter of the 'google_map' shortcode in all versions …

Oct 15, 2025
CVE-2025-11196
4.3 MEDIUM

The External Login plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.11.2 due to the 'exlog_test_connection' AJAX …

Oct 15, 2025
CVE-2025-11177
7.5 HIGH

The External Login plugin for WordPress is vulnerable to SQL Injection via the 'log' parameter in all versions up to, and including, 1.11.2 due to …

Oct 15, 2025
CVE-2025-10754
7.2 HIGH

The DocoDoco Store Locator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functionality in …

Oct 15, 2025
CVE-2025-10743
7.5 HIGH

The Outdoor plugin for WordPress is vulnerable to SQL Injection via the 'edit' action in all versions up to, and including, 1.3.2 due to insufficient …

Oct 15, 2025
CVE-2025-10730
6.5 MEDIUM

The Wp tabber widget plugin for WordPress is vulnerable to SQL Injection via the 'wp-tabber-widget' shortcode in all versions up to, and including, 4.0 due …

Oct 15, 2025
CVE-2025-10682
6.5 MEDIUM

The TARIFFUXX plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4. This is due to insufficient neutralization of user-supplied …

Oct 15, 2025
CVE-2025-10660
6.5 MEDIUM

The WP Dashboard Chat plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.0.3 due …

Oct 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.