2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-22389HIGH7.2When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to...
CVE-2024-22093HIGH8.7When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iContro...
CVE-2024-21849HIGH7.5 When an Advanced WAF/ASM security policy and a Websockets profile are configured on a virtual server, undisclosed tra...
CVE-2024-21789HIGH7.5 When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server, undisclosed requests can cause an i...
CVE-2024-21771HIGH7.5 For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic agai...
CVE-2024-21763HIGH7.5 When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vector and bad actor detection, undisclose...
CVE-2024-0568HIGH8.8 CWE-287: Improper Authentication vulnerability exists that could cause unauthorized tampering of device configuration o...
CVE-2024-25213HIGH7.2Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /edit.php...
CVE-2024-25212HIGH7.2Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /delete.p...
CVE-2024-23789HIGH8.8Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent una...
CVE-2024-23788HIGH8.1Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1....
CVE-2024-23783HIGH8.8Improper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 ...
CVE-2024-24697HIGH7.8Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of pr...
CVE-2024-25121HIGH7.1TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO...
CVE-2024-24814HIGH7.5mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that imp...
CVE-2024-24751HIGH8.8sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected...
CVE-2024-1354HIGH8A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol...
CVE-2024-21420HIGH8.8Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2024-21412HIGH8.1Internet Shortcut Files Security Feature Bypass Vulnerability
CVE-2024-21406HIGH7.5Windows Printing Service Spoofing Vulnerability
CVE-2024-21405HIGH7Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
CVE-2024-21404HIGH7.5.NET Denial of Service Vulnerability
CVE-2024-21402HIGH7.1Microsoft Outlook Elevation of Privilege Vulnerability
CVE-2024-21396HIGH7.6Dynamics 365 Sales Spoofing Vulnerability
CVE-2024-21395HIGH8.2Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now