2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0007 | MEDIUM | 4.8 | 0.4% | Feb 14, 2024 | A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-... |
| CVE-2024-24990 | HIGH | 7.5 | 0.9% | Feb 14, 2024 | When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker p... |
| CVE-2024-24989 | HIGH | 7.5 | 1.1% | Feb 14, 2024 | When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker p... |
| CVE-2024-24966 | MEDIUM | 5.5 | 0.2% | Feb 14, 2024 | When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly autho... |
| CVE-2024-24775 | HIGH | 7.5 | 0.5% | Feb 14, 2024 | When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traf... |
| CVE-2024-23982 | HIGH | 7.5 | 0.5% | Feb 14, 2024 | When a BIG-IP PEM classification profile is configured on a UDP virtual server, undisclosed requests can cause the Tr... |
| CVE-2024-23979 | HIGH | 7.5 | 0.3% | Feb 14, 2024 | When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is co... |
| CVE-2024-23976 | MEDIUM | 6 | 0.2% | Feb 14, 2024 | When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Applianc... |
| CVE-2024-23805 | HIGH | 7.5 | 0.5% | Feb 14, 2024 | Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Application Visibility an... |
| CVE-2024-23607 | MEDIUM | 5.5 | 0.5% | Feb 14, 2024 | A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read fil... |
| CVE-2024-23603 | LOW | 3.8 | 0.3% | Feb 14, 2024 | An SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. Note: Software v... |
| CVE-2024-23314 | HIGH | 7.5 | 0.5% | Feb 14, 2024 | When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management M... |
| CVE-2024-23308 | HIGH | 7.5 | 0.5% | Feb 14, 2024 | When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, un... |
| CVE-2024-23306 | HIGH | 7.1 | 0.2% | Feb 14, 2024 | A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files. Note: S... |
| CVE-2024-22389 | HIGH | 7.2 | 0.5% | Feb 14, 2024 | When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to... |
| CVE-2024-22093 | HIGH | 8.7 | 0.8% | Feb 14, 2024 | When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iContro... |
| CVE-2024-21849 | HIGH | 7.5 | 0.5% | Feb 14, 2024 | When an Advanced WAF/ASM security policy and a Websockets profile are configured on a virtual server, undisclosed tra... |
| CVE-2024-21789 | HIGH | 7.5 | 0.5% | Feb 14, 2024 | When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server, undisclosed requests can cause an i... |
| CVE-2024-21782 | MEDIUM | 6.7 | 0.2% | Feb 14, 2024 | BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but d... |
| CVE-2024-21771 | HIGH | 7.5 | 0.5% | Feb 14, 2024 | For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic agai... |
| CVE-2024-21763 | HIGH | 7.5 | 0.5% | Feb 14, 2024 | When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vector and bad actor detection, undisclose... |
| CVE-2024-0568 | HIGH | 8.8 | 0.3% | Feb 14, 2024 | CWE-287: Improper Authentication vulnerability exists that could cause unauthorized tampering of device configuration o... |
| CVE-2024-25226 | MEDIUM | 6.1 | 0.4% | Feb 14, 2024 | A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scri... |
| CVE-2024-25225 | MEDIUM | 5.4 | 0.4% | Feb 14, 2024 | A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scri... |
| CVE-2024-25224 | MEDIUM | 5.4 | 0.4% | Feb 14, 2024 | A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scri... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now