2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-31156HIGH8 A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility tha...
CVE-2024-28889MEDIUM5.9 When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffi...
CVE-2024-28883HIGH7.4An origin validation vulnerability exists in BIG-IP APM browser network access VPN client for Windows, macOS and ...
CVE-2024-28132MEDIUM4.4 Exposure of Sensitive Information vulnerability exists in the GSLB container, which may allow an authenticated attacker...
CVE-2024-27202MEDIUM4.7 A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility ...
CVE-2024-26579CRITICAL9.8Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1....
CVE-2024-26026HIGH7.5An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have ...
CVE-2024-25560HIGH7.5 When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM)...
CVE-2024-25526HIGH8.1RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the project_id parameter at /Proje...
CVE-2024-25525CRITICAL9.8RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the filename parameter at /WorkFlo...
CVE-2024-25524CRITICAL9.4RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter ...
CVE-2024-25523CRITICAL9.8RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /filemana...
CVE-2024-25522CRITICAL9.4RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the office_missive_id parameter at...
CVE-2024-25521CRITICAL9.4RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the txt_keyword parameter at get_c...
CVE-2024-25520CRITICAL9.8RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /SysManage/sys...
CVE-2024-25519CRITICAL9.8RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the idlist parameter at /WorkFlow/...
CVE-2024-25518CRITICAL9.4RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /Work...
CVE-2024-25517CRITICAL9.8RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the tbTable argument at /WebUtilit...
CVE-2024-25515HIGH7.3RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter ...
CVE-2024-21793HIGH7.5An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which hav...
CVE-2024-4652MEDIUM6.1A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System...
CVE-2024-4651MEDIUM6.1A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management S...
CVE-2024-4650MEDIUM6.1A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. This v...
CVE-2024-4649MEDIUM6.1A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0. T...
CVE-2024-4233MEDIUM4.3Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce, Tyche Softwares A...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now