2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-61951HIGH8.7Undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  This issue may occur when a Datagr...
CVE-2025-61938HIGH8.7When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than 1024 characters in length for th...
CVE-2025-60016HIGH8.7When Diffie-Hellman (DH) group Elliptic Curve Cryptography (ECC) Brainpool curves are configured in an SSL profile's Cip...
CVE-2025-60015MEDIUM6.9An out-of-bounds write vulnerability exists in F5OS-A and F5OS-C that could lead to memory corruption.  Note: Softw...
CVE-2025-60013MEDIUM4.6When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with sp...
CVE-2025-59781HIGH8.7When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undisclosed DNS queries can cause an increas...
CVE-2025-59778HIGH7.7When the Allowed IP Addresses feature is configured on the F5OS-C partition control plane, undisclosed traffic can cause...
CVE-2025-59483MEDIUM6.5A validation vulnerability exists in an undisclosed URL in the Configuration utility.  Note: Software versions which hav...
CVE-2025-59481HIGH8.7A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authentica...
CVE-2025-59478HIGH8.7When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a virtual server, undisclosed requests can...
CVE-2025-59269HIGH8.4A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that...
CVE-2025-59268MEDIUM6.9On the BIG-IP system, undisclosed endpoints that contain static non-sensitive information are accessible to an unauthent...
CVE-2025-58474MEDIUM5.3When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or when an...
CVE-2025-58424MEDIUM6.3On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols which d...
CVE-2025-58153MEDIUM5.9Under undisclosed traffic conditions along with conditions beyond the attacker's control, hardware systems with a High-S...
CVE-2025-58120HIGH8.7When HTTP/2 Ingress is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. ...
CVE-2025-58096HIGH8.2When the database variable tm.tcpudptxchecksum is configured as non-default value Software-only on a BIG-IP system, undi...
CVE-2025-56746LOW2.2Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabli...
CVE-2025-55670HIGH7.1On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause th...
CVE-2025-55669HIGH8.7When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured on a virtual server...
CVE-2025-55036HIGH8.7When BIG-IP SSL Orchestrator explicit forward proxy is configured on a virtual server and the proxy connect feature is e...
CVE-2025-54858HIGH8.7When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed ...
CVE-2025-54854HIGH8.7When a BIG-IP APM OAuth access profile (Resource Server or Resource Client) is configured on a virtual server, undisclos...
CVE-2025-54805MEDIUM6.5When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can ...
CVE-2025-54755MEDIUM4.9A directory traversal vulnerability exists in TMUI that allows a highly privileged authenticated attacker to access file...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now