2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31156 | HIGH | 8 | 0.6% | May 8, 2024 | A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility tha... |
| CVE-2024-28889 | MEDIUM | 5.9 | 0.4% | May 8, 2024 | When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffi... |
| CVE-2024-28883 | HIGH | 7.4 | 0.2% | May 8, 2024 | An origin validation vulnerability exists in BIG-IP APM browser network access VPN client for Windows, macOS and ... |
| CVE-2024-28132 | MEDIUM | 4.4 | 0.2% | May 8, 2024 | Exposure of Sensitive Information vulnerability exists in the GSLB container, which may allow an authenticated attacker... |
| CVE-2024-27202 | MEDIUM | 4.7 | 0.3% | May 8, 2024 | A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility ... |
| CVE-2024-26579 | CRITICAL | 9.8 | 1.1% | May 8, 2024 | Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.... |
| CVE-2024-26026 | HIGH | 7.5 | 7.2% | May 8, 2024 | An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have ... |
| CVE-2024-25560 | HIGH | 7.5 | 0.5% | May 8, 2024 | When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM)... |
| CVE-2024-25526 | HIGH | 8.1 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the project_id parameter at /Proje... |
| CVE-2024-25525 | CRITICAL | 9.8 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the filename parameter at /WorkFlo... |
| CVE-2024-25524 | CRITICAL | 9.4 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter ... |
| CVE-2024-25523 | CRITICAL | 9.8 | 0.7% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /filemana... |
| CVE-2024-25522 | CRITICAL | 9.4 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the office_missive_id parameter at... |
| CVE-2024-25521 | CRITICAL | 9.4 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the txt_keyword parameter at get_c... |
| CVE-2024-25520 | CRITICAL | 9.8 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /SysManage/sys... |
| CVE-2024-25519 | CRITICAL | 9.8 | 0.7% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the idlist parameter at /WorkFlow/... |
| CVE-2024-25518 | CRITICAL | 9.4 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /Work... |
| CVE-2024-25517 | CRITICAL | 9.8 | 0.7% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the tbTable argument at /WebUtilit... |
| CVE-2024-25515 | HIGH | 7.3 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter ... |
| CVE-2024-21793 | HIGH | 7.5 | 7.1% | May 8, 2024 | An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which hav... |
| CVE-2024-4652 | MEDIUM | 6.1 | 0.4% | May 8, 2024 | A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System... |
| CVE-2024-4651 | MEDIUM | 6.1 | 0.5% | May 8, 2024 | A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management S... |
| CVE-2024-4650 | MEDIUM | 6.1 | 0.4% | May 8, 2024 | A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. This v... |
| CVE-2024-4649 | MEDIUM | 6.1 | 0.4% | May 8, 2024 | A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0. T... |
| CVE-2024-4233 | MEDIUM | 4.3 | 0.3% | May 8, 2024 | Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce, Tyche Softwares A... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now