2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-0007MEDIUM4.8A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-...
CVE-2024-24990HIGH7.5When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker p...
CVE-2024-24989HIGH7.5When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker p...
CVE-2024-24966MEDIUM5.5 When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly autho...
CVE-2024-24775HIGH7.5When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traf...
CVE-2024-23982HIGH7.5 When a BIG-IP PEM classification profile is configured on a UDP virtual server, undisclosed requests can cause the Tr...
CVE-2024-23979HIGH7.5 When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is co...
CVE-2024-23976MEDIUM6When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Applianc...
CVE-2024-23805HIGH7.5 Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Application Visibility an...
CVE-2024-23607MEDIUM5.5 A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read fil...
CVE-2024-23603LOW3.8 An SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. Note: Software v...
CVE-2024-23314HIGH7.5When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management M...
CVE-2024-23308HIGH7.5 When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, un...
CVE-2024-23306HIGH7.1A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files.  Note: S...
CVE-2024-22389HIGH7.2When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to...
CVE-2024-22093HIGH8.7When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iContro...
CVE-2024-21849HIGH7.5 When an Advanced WAF/ASM security policy and a Websockets profile are configured on a virtual server, undisclosed tra...
CVE-2024-21789HIGH7.5 When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server, undisclosed requests can cause an i...
CVE-2024-21782MEDIUM6.7BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but d...
CVE-2024-21771HIGH7.5 For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic agai...
CVE-2024-21763HIGH7.5 When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vector and bad actor detection, undisclose...
CVE-2024-0568HIGH8.8 CWE-287: Improper Authentication vulnerability exists that could cause unauthorized tampering of device configuration o...
CVE-2024-25226MEDIUM6.1A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scri...
CVE-2024-25225MEDIUM5.4A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scri...
CVE-2024-25224MEDIUM5.4A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scri...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now