2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61951 | HIGH | 8.7 | 0.2% | Oct 15, 2025 | Undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. This issue may occur when a Datagr... |
| CVE-2025-61938 | HIGH | 8.7 | 0.3% | Oct 15, 2025 | When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than 1024 characters in length for th... |
| CVE-2025-60016 | HIGH | 8.7 | 0.4% | Oct 15, 2025 | When Diffie-Hellman (DH) group Elliptic Curve Cryptography (ECC) Brainpool curves are configured in an SSL profile's Cip... |
| CVE-2025-59781 | HIGH | 8.7 | 0.3% | Oct 15, 2025 | When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undisclosed DNS queries can cause an increas... |
| CVE-2025-59778 | HIGH | 7.7 | 0.3% | Oct 15, 2025 | When the Allowed IP Addresses feature is configured on the F5OS-C partition control plane, undisclosed traffic can cause... |
| CVE-2025-59481 | HIGH | 8.7 | 0.4% | Oct 15, 2025 | A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authentica... |
| CVE-2025-59478 | HIGH | 8.7 | 0.3% | Oct 15, 2025 | When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a virtual server, undisclosed requests can... |
| CVE-2025-59269 | HIGH | 8.4 | 0.3% | Oct 15, 2025 | A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that... |
| CVE-2025-58120 | HIGH | 8.7 | 0.3% | Oct 15, 2025 | When HTTP/2 Ingress is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. ... |
| CVE-2025-58096 | HIGH | 8.2 | 0.3% | Oct 15, 2025 | When the database variable tm.tcpudptxchecksum is configured as non-default value Software-only on a BIG-IP system, undi... |
| CVE-2025-55670 | HIGH | 7.1 | 0.3% | Oct 15, 2025 | On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause th... |
| CVE-2025-55669 | HIGH | 8.7 | 0.4% | Oct 15, 2025 | When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured on a virtual server... |
| CVE-2025-55036 | HIGH | 8.7 | 0.3% | Oct 15, 2025 | When BIG-IP SSL Orchestrator explicit forward proxy is configured on a virtual server and the proxy connect feature is e... |
| CVE-2025-54858 | HIGH | 8.7 | 0.3% | Oct 15, 2025 | When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed ... |
| CVE-2025-54854 | HIGH | 8.7 | 0.3% | Oct 15, 2025 | When a BIG-IP APM OAuth access profile (Resource Server or Resource Client) is configured on a virtual server, undisclos... |
| CVE-2025-54479 | HIGH | 8.7 | 0.3% | Oct 15, 2025 | When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, undisclosed requests ... |
| CVE-2025-53868 | HIGH | 8.7 | 0.4% | Oct 15, 2025 | When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to by... |
| CVE-2025-53856 | HIGH | 8.7 | 0.3% | Oct 15, 2025 | When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object use... |
| CVE-2025-53474 | HIGH | 8.7 | 0.3% | Oct 15, 2025 | When an iRule using an ILX::call command is configured on a virtual server, undisclosed traffic can cause the Traffic Ma... |
| CVE-2025-48008 | HIGH | 8.7 | 0.4% | Oct 15, 2025 | When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with ... |
| CVE-2025-47150 | HIGH | 7.1 | 0.3% | Oct 15, 2025 | When SNMP is configured on F5OS Appliance and Chassis systems, undisclosed requests can cause an increase in SNMP memory... |
| CVE-2025-47148 | HIGH | 7.1 | 0.4% | Oct 15, 2025 | When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Ident... |
| CVE-2025-46706 | HIGH | 8.7 | 0.4% | Oct 15, 2025 | When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an ... |
| CVE-2025-41430 | HIGH | 8.7 | 0.3% | Oct 15, 2025 | When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to termi... |
| CVE-2025-11722 | HIGH | 7.5 | 0.6% | Oct 15, 2025 | The Woocommerce Category and Products Accordion Panel plugin for WordPress is vulnerable to Local File Inclusion in all ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now