Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
| CVE | Vendor | Product | Vulnerability | CVSS | Added | Due per BOD 22-01 | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2026-94127 | F5 | BIG-IP APM | F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution. | 9.8 CNA | 2026-09-22 | 2026-09-25 | Unknown |
| CVE-2025-53521 | F5 | BIG-IP | F5 BIG-IP Stack-Based Buffer Overflow Vulnerability F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution. | 9.8 CNA | 2026-03-27 | 2026-03-30 | Unknown |
| CVE-2023-46747 | F5 | BIG-IP Configuration Utility | F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748. | 9.8 CNA | 2023-10-31 | 2023-11-21 | Known |
| CVE-2023-46748 | F5 | BIG-IP Configuration Utility | F5 BIG-IP Configuration Utility SQL Injection Vulnerability F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747. | 8.8 CNA | 2023-10-31 | 2023-11-21 | Unknown |
| CVE-2022-1388 | F5 | BIG-IP | F5 BIG-IP Missing Authentication Vulnerability F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services. | 9.8 CNA | 2022-05-10 | 2022-05-31 | Known |
| CVE-2021-22991 | F5 | BIG-IP Traffic Management Microkernel | F5 BIG-IP Traffic Management Microkernel Buffer Overflow The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls. | 9.8 CISA | 2022-01-18 | 2022-02-01 | Unknown |
| CVE-2021-22986 | F5 | BIG-IP and BIG-IQ Centralized Management | F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services. | 9.8 CISA | 2021-11-03 | 2021-11-17 | Known |
| CVE-2020-5902 | F5 | BIG-IP | F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Known |