Known vulnerabilities in BIG-IQ Centralized Management - page 2

Software CPE: cpe:2.3:a:f5_networks:big-iq:*:*:*:*:*:*:*:*
Total vulnerabilities: 125
Public exploits: 18
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting BIG-IQ Centralized Management BIG-IQ Centralized Management is affected by 125 known vulnerabilities: 9 high, 51 medium, 65 low Critical High Medium Low

Vulnerabilities (125)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU98759 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-47139
CWE-79 Low
No
No
8.2.0.1, 8.3.0 16.10.2024 SB20241016110
#VU92262 - Exposure of sensitive information to an unauthorized actor
CVE-2024-37891
CWE-200 Low
No
No
- 19.06.2024 SB2024061955
SB20240625146
SB2024062605
and 193 more
#VU82544 - Authentication Bypass Using an Alternate Path or Channel
CVE-2023-46747
CWE-288 High
Available
Exploited
cvssv3 score 27.10.2023 SB2023102726
SB2024080142
#VU78885 - Improper input validation
CVE-2023-38419
CWE-20 Medium
No
No
- 02.08.2023 SB2023080285
#VU76651 - Resource Management Errors
CVE-2023-2650
CWE-399 Medium
No
No
- 30.05.2023 SB2023053040
SB2023053044
SB2023053045
and 131 more
#VU71878 - Incorrect Permission Assignment for Critical Resource
CVE-2023-22326
CWE-732 Low
No
No
- 06.02.2023 SB2023020665
#VU66726 - Permissions, Privileges, and Access Controls
CVE-2022-31676
CWE-264 Low
No
No
- 23.08.2022 SB2022082317
SB2022082416
SB2022082423
and 36 more
#VU64063 - Out-of-bounds write
CVE-2022-28734
CWE-787 Medium
No
No
- 08.06.2022 SB2022060810
SB2022061540
SB2022061566
and 36 more
#VU61393 - UNIX Symbolic Link (Symlink) Following
CVE-2021-23177
CWE-61 Low
No
No
- 15.03.2022 SB2022031530
SB2022031601
SB2022032445
and 25 more
#VU61286 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-22720
CWE-444 Medium
No
No
- 14.03.2022 SB2022031416
SB2022031504
SB2022031724
and 56 more
#VU48942 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2020-27216
CWE-362 Low
No
No
- 23.10.2020 SB2020121307
SB2020121308
SB2021012011
and 27 more
#VU47777 - Missing Encryption of Sensitive Data
CVE-2020-14781
CWE-311 Low
No
No
- 21.10.2020 SB2020102109
SB2020102110
SB2020102801
and 48 more
#VU47780 - Improper input validation
CVE-2020-14779
CWE-20 Low
No
No
- 21.10.2020 SB2020102109
SB2020102110
SB2020102801
and 46 more
#VU27230 - Improper input validation
CVE-2020-2756
CWE-20 Low
No
No
- 23.04.2020 SB2020042301
SB2020042302
SB2020042316
and 50 more
#VU27231 - Improper input validation
CVE-2020-2757
CWE-20 Low
No
No
- 23.04.2020 SB2020042301
SB2020042302
SB2020042316
and 49 more
#VU16727 - Use After Free
CVE-2018-1000878
CWE-416 Low
No
No
- 27.12.2018 SB2018122014
SB2018122801
SB2019041207
and 13 more
#VU16726 - Double Free
CVE-2018-1000877
CWE-415 Low
No
No
- 20.12.2018 SB2018122014
SB2018122801
SB2019041207
and 13 more
#VU15950 - NULL Pointer Dereference
CVE-2016-10209
CWE-476 Low
No
No
- 19.11.2018 SB2017091705
SB2018111908
SB2018122801
and 4 more
#VU14322 - Permissions, Privileges, and Access Controls
CVE-2018-2952
CWE-264 Low
No
No
- 13.08.2018 SB2018080913
SB2018081307
SB2018082404
and 17 more
#VU11835 - Heap-based Buffer Overflow
CVE-2018-6913
CWE-122 Low
No
No
- 16.04.2018 SB2018041601
SB2019090611
SB2018041717
and 15 more


Showing elements 21 - 40 out of 125