Lucene search

K

F5 Networks, Inc. Security Vulnerabilities

nessus
nessus

F5 Networks BIG-IP : Intel BIOS vulnerability (K16162257)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K16162257 advisory. Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to ...

7.8CVSS

7.6AI Score

0.0004EPSS

2022-06-22 12:00 AM
20
vulnrichment
vulnrichment

CVE-2023-30306

An issue discovered in Mercury x30g, Mercury YR1800XG routers allows attackers to hijack TCP sessions which could lead to a denial of...

6.8AI Score

EPSS

1976-01-01 12:00 AM
1
cve
cve

CVE-2023-30306

An issue discovered in Mercury x30g, Mercury YR1800XG routers allows attackers to hijack TCP sessions which could lead to a denial of...

7AI Score

EPSS

2024-05-28 08:16 PM
20
zeroscience
zeroscience

Elber Signum DVB-S/S2 IRD For Radio Networks 1.999 Authentication Bypass

Title: Elber Signum DVB-S/S2 IRD For Radio Networks 1.999 Authentication Bypass Advisory ID: ZSL-2024-5814 Type: Local/Remote Impact: Security Bypass, Privilege Escalation, System Access, DoS Risk: (5/5) Release Date: 17.04.2024 Summary The SIGNUM controller from Elber satellite equipment...

7.7AI Score

2024-04-17 12:00 AM
45
nessus
nessus

F5 Networks BIG-IP : Intel processors vulnerability (K29100014)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K29100014 advisory. Improper conditions check in multiple Intel Processors may allow an authenticated user to potentially enable...

5.3CVSS

5.7AI Score

0.0005EPSS

2023-11-03 12:00 AM
6
nessus
nessus

F5 Networks BIG-IP : Intel CPU vulnerability (K82356391)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K82356391 advisory. Improper buffer restrictions in BIOS firmware for some Intel(R) Processors may allow a privileged user to ...

6.7CVSS

7AI Score

0.0004EPSS

2023-11-03 12:00 AM
7
nessus
nessus

F5 Networks BIG-IP : Apache HTTPD vulnerability (K78131906)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K78131906 advisory. A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of...

5.9CVSS

7.8AI Score

0.011EPSS

2023-11-03 12:00 AM
13
nessus
nessus

F5 Networks BIG-IP : RetBleed CPU vulnerability (K83713003)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K83713003 advisory. Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their ...

6.5CVSS

7.3AI Score

0.001EPSS

2022-08-02 12:00 AM
38
nessus
nessus

F5 Networks BIG-IP : Intel BIOS vulnerability (K87351324)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K87351324 advisory. Out-of-bounds write in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user...

6.7CVSS

6.5AI Score

0.0004EPSS

2022-06-22 12:00 AM
31
nessus
nessus

F5 Networks BIG-IP : Linux kernel vulnerability (K32380005)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K32380005 advisory. The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability,...

5.3CVSS

6AI Score

0.002EPSS

2021-10-28 12:00 AM
61
cvelist
cvelist

CVE-2024-4362 SiteOrigin Widgets Bundle <= 1.60.0 - - Authenticated (Contributor+) Stored Cross-Site Scripting via 'siteorigin_widget' Shortcode

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteorigin_widget' shortcode in all versions up to, and including, 1.60.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible....

6.4CVSS

5.9AI Score

0.001EPSS

2024-05-22 08:31 AM
cve
cve

CVE-2024-2973

An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router or conductor running with a redundant peer allows a network based attacker to bypass authentication and take full control of the device. Only routers or conductors that are running in....

10CVSS

7.2AI Score

0.001EPSS

2024-06-27 09:15 PM
21
cve
cve

CVE-2024-4611

The AppPresser plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'decrypt_value' and on the 'doCookieAuth' functions in all versions up to, and including, 4.3.2. This makes it possible for unauthenticated attackers to log in as any existing user on the...

8.1CVSS

6.8AI Score

0.001EPSS

2024-05-29 05:16 AM
3
vulnrichment
vulnrichment

CVE-2024-4611 AppPresser <= 4.3.2 - Improper Missing Encryption Exception Handling to Authentication Bypass

The AppPresser plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'decrypt_value' and on the 'doCookieAuth' functions in all versions up to, and including, 4.3.2. This makes it possible for unauthenticated attackers to log in as any existing user on the...

8.1CVSS

6.9AI Score

0.001EPSS

2024-05-29 04:30 AM
1
cvelist
cvelist

CVE-2024-4611 AppPresser <= 4.3.2 - Improper Missing Encryption Exception Handling to Authentication Bypass

The AppPresser plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'decrypt_value' and on the 'doCookieAuth' functions in all versions up to, and including, 4.3.2. This makes it possible for unauthenticated attackers to log in as any existing user on the...

8.1CVSS

8AI Score

0.001EPSS

2024-05-29 04:30 AM
2
nessus
nessus

F5 Networks BIG-IP : procps-ng vulnerability (K00409335)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K00409335 advisory. procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME...

7.3CVSS

8.6AI Score

0.0004EPSS

2023-11-02 12:00 AM
7
nessus
nessus

F5 Networks BIG-IP : Linux kernel vulnerability (K01043241)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K01043241 advisory. net/netfilter/nfnetlink_cthelper.c in the Linux kernel through 4.14.4 does not require the CAP_NET_ADMIN capability...

7.8CVSS

7.1AI Score

0.0004EPSS

2023-11-02 12:00 AM
11
nessus
nessus

F5 Networks BIG-IP : AMD processors vulnerability (K43357358)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K43357358 advisory. A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to...

6.5CVSS

6.3AI Score

0.001EPSS

2022-07-13 12:00 AM
20
nessus
nessus

F5 Networks BIG-IP : Eclipse Jetty vulnerabilities (K10002140)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the K10002140 advisory. In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default ...

9.8CVSS

9.8AI Score

0.012EPSS

2022-04-05 12:00 AM
42
nessus
nessus

F5 Networks BIG-IP : Apache Tomcat vulnerability (K32469285)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K32469285 advisory. Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP ...

5.3CVSS

6.3AI Score

0.123EPSS

2021-10-28 12:00 AM
23
nessus
nessus

F5 Networks BIG-IP : Intel processor vulnerabilities (K41043270)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the K41043270 advisory. Observable response discrepancy in floating-point operations for some Intel(R) Processors may allow an ...

6.5CVSS

7AI Score

0.0005EPSS

2021-10-28 12:00 AM
13
nessus
nessus

VMware vCenter Detect

VMware vCenter is running on the remote host. It is an enterprise- grade computer virtualization product from VMware,...

1.9AI Score

2012-11-27 12:00 AM
18
zeroscience
zeroscience

Elber Signum DVB-S/S2 IRD For Radio Networks 1.999 Device Config

Title: Elber Signum DVB-S/S2 IRD For Radio Networks 1.999 Device Config Advisory ID: ZSL-2024-5815 Type: Local/Remote Impact: Security Bypass, Privilege Escalation, System Access, DoS Risk: (5/5) Release Date: 17.04.2024 Summary The SIGNUM controller from Elber satellite equipment demodulates...

7.3AI Score

2024-04-17 12:00 AM
72
nessus
nessus

F5 Networks BIG-IP : Apache Tomcat vulnerability (K000138178)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K000138178 advisory. Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from...

5.3CVSS

6.7AI Score

0.01EPSS

2024-01-17 12:00 AM
18
nessus
nessus

F5 Networks BIG-IP : Apache Struts vulnerabilities (K35226442)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the K35226442 advisory. An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when ...

9.8CVSS

9.3AI Score

0.953EPSS

2023-11-03 12:00 AM
31
nessus
nessus

F5 Networks BIG-IP : Apache Tomcat vulnerability (K24551552)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K24551552 advisory. When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was...

7.5CVSS

7.8AI Score

0.004EPSS

2023-11-03 12:00 AM
17
nessus
nessus

F5 Networks BIG-IP : Linux kernel vulnerability (K07721343)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K07721343 advisory. A flaw was found in Linux kernel's KVM virtualization subsystem. The VMX code does not restore the GDT.LIMIT to the...

7.8CVSS

7.7AI Score

0.001EPSS

2023-11-02 12:00 AM
4
nessus
nessus

F5 Networks BIG-IP : Intel BIOS vulnerability (K000137202)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K000137202 advisory. Improper initialization in the BIOS firmware for some Intel(R) Processors may allow a privileged user to ...

6.1CVSS

4.4AI Score

0.0004EPSS

2023-10-11 12:00 AM
6
nessus
nessus

F5 Networks BIG-IP : Intel BIOS vulnerability (K000130240)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K000130240 advisory. Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to ...

6.8AI Score

0.0004EPSS

2023-06-02 12:00 AM
12
nessus
nessus

F5 Networks BIG-IP : Intel BIOS vulnerability (K04303225)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K04303225 advisory. Uncaught exception in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially...

7.8CVSS

7.5AI Score

0.0004EPSS

2022-06-22 12:00 AM
27
nessus
nessus

F5 Networks BIG-IP : Intel BIOS vulnerability (K14454359)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K14454359 advisory. Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially...

7.8CVSS

7.6AI Score

0.0004EPSS

2022-06-22 12:00 AM
39
nessus
nessus

F5 Networks BIG-IP : Linux kernel vulnerability (K84900646)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K84900646 advisory. A flaw was found in the Linux kernel before 5.9-rc4. A failure of the file system metadata validator in XFS can...

5.5CVSS

6.3AI Score

0.0004EPSS

2021-10-28 12:00 AM
22
nessus
nessus

F5 Networks BIG-IP : Java SE vulnerability (K85742355)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K85742355 advisory. Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that...

3.7CVSS

5.2AI Score

0.001EPSS

2023-11-03 12:00 AM
20
nessus
nessus

F5 Networks BIG-IP : Apache Struts vulnerabilities (K24608264)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the K24608264 advisory. Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code ...

9.8CVSS

10AI Score

0.973EPSS

2023-11-03 12:00 AM
34
nessus
nessus

F5 Networks BIG-IP : Linux kernel vulnerability (K13213573)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K13213573 advisory. Integer overflow in fs/aio.c in the Linux kernel before 3.4.1 allows local users to cause a denial of service or...

7.8CVSS

7.9AI Score

0.0004EPSS

2023-11-02 12:00 AM
12
nessus
nessus

F5 Networks BIG-IP : IPsec IKEv1 vulnerability (K42378447)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K42378447 advisory. The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks. Reusing a key...

5.9CVSS

5.7AI Score

0.003EPSS

2023-11-02 12:00 AM
4
nessus
nessus

F5 Networks BIG-IP : Rowhammer hardware vulnerability (K60570139)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K60570139 advisory. Modern DRAM chips (DDR4 and LPDDR4 after 2015) are affected by a vulnerability in deployment of internal ...

9CVSS

9AI Score

0.002EPSS

2023-11-02 12:00 AM
2
nessus
nessus

F5 Networks BIG-IP : Linux kernel vulnerability (K40540405)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K40540405 advisory. The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a...

7.8CVSS

7.9AI Score

0.0004EPSS

2023-11-02 12:00 AM
5
nessus
nessus

F5 Networks BIG-IP : procps-ng vulnerability (K16124204)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K16124204 advisory. procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in...

7.8CVSS

9.3AI Score

0.0005EPSS

2023-11-02 12:00 AM
4
nessus
nessus

F5 Networks BIG-IP : Linux kernel vulnerability (K15412203)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K15412203 advisory. The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through ...

7.8CVSS

7.5AI Score

0.001EPSS

2023-11-02 12:00 AM
8
nessus
nessus

F5 Networks BIG-IP : Intel processor vulnerability (K000133630)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K000133630 advisory. Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to ...

8.2CVSS

6.8AI Score

0.0004EPSS

2023-10-12 12:00 AM
9
nessus
nessus

F5 Networks BIG-IP : Python urllib.parse vulnerability (K000135921)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K000135921 advisory. An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by...

7.5CVSS

8.1AI Score

0.001EPSS

2023-08-21 12:00 AM
28
nessus
nessus

F5 Networks BIG-IP : Apache Tomcat vulnerability (K000135262)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K000135262 advisory. The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to...

7.5CVSS

7.4AI Score

0.034EPSS

2023-06-29 12:00 AM
14
nessus
nessus

F5 Networks BIG-IP : Intel Processor vulnerability (K11601010)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K11601010 advisory. Observable behavioral discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable...

5.5CVSS

5.3AI Score

0.0004EPSS

2022-10-25 12:00 AM
11
nessus
nessus

F5 Networks BIG-IP : Intel BIOS vulnerability (K53252134)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K53252134 advisory. Unchecked return value in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially...

5.5CVSS

5.2AI Score

0.0004EPSS

2022-07-21 12:00 AM
16
nessus
nessus

F5 Networks BIG-IP : Intel processors vulnerability (K14335949)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K14335949 advisory. Observable behavioral in power management throttling for some Intel(R) Processors may allow an authenticated user...

6.5CVSS

6.2AI Score

0.001EPSS

2022-07-13 12:00 AM
14
nessus
nessus

F5 Networks BIG-IP : Intel BIOS vulnerability (K55051330)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K55051330 advisory. Improper access control in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged...

7.8CVSS

7.6AI Score

0.0004EPSS

2022-06-22 12:00 AM
25
nessus
nessus

Juniper Junos OS Evolved DoS (JSA69505)

The version of Junos OS installed on the remote host is affected by a vulnerability as referenced in the JSA69505 advisory. An Improper Check for Unusual or Exceptional Conditions vulnerability in the packetIO daemon of Juniper Networks Junos OS Evolved on PTX10003, PTX10004, and PTX10008...

7.5CVSS

7.7AI Score

0.001EPSS

2022-04-25 12:00 AM
18
vulnrichment
vulnrichment

CVE-2024-25095 WordPress Easy Forms for Mailchimp plugin <= 6.9.0 - Sensitive Data Exposure via Log File vulnerability

Insertion of Sensitive Information into Log File vulnerability in Code Parrots Easy Forms for Mailchimp.This issue affects Easy Forms for Mailchimp: from n/a through...

7.5CVSS

7.4AI Score

0.001EPSS

2024-06-04 06:37 PM
osv
osv

CVE-2019-25093

A vulnerability, which was classified as problematic, was found in dragonexpert Recent Threads on Index. Affected is the function recentthread_list_threads of the file inc/plugins/recentthreads/hooks.php of the component Setting Handler. The manipulation of the argument recentthread_forumskip...

5.4CVSS

6.2AI Score

0.001EPSS

2023-01-02 11:15 AM
6
Total number of security vulnerabilities315004