2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22389 | HIGH | 7.2 | 0.5% | Feb 14, 2024 | When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to... |
| CVE-2024-22093 | HIGH | 8.7 | 0.8% | Feb 14, 2024 | When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iContro... |
| CVE-2024-21849 | HIGH | 7.5 | 0.5% | Feb 14, 2024 | When an Advanced WAF/ASM security policy and a Websockets profile are configured on a virtual server, undisclosed tra... |
| CVE-2024-21789 | HIGH | 7.5 | 0.5% | Feb 14, 2024 | When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server, undisclosed requests can cause an i... |
| CVE-2024-21771 | HIGH | 7.5 | 0.5% | Feb 14, 2024 | For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic agai... |
| CVE-2024-21763 | HIGH | 7.5 | 0.5% | Feb 14, 2024 | When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vector and bad actor detection, undisclose... |
| CVE-2024-0568 | HIGH | 8.8 | 0.3% | Feb 14, 2024 | CWE-287: Improper Authentication vulnerability exists that could cause unauthorized tampering of device configuration o... |
| CVE-2024-25213 | HIGH | 7.2 | 0.7% | Feb 14, 2024 | Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /edit.php... |
| CVE-2024-25212 | HIGH | 7.2 | 0.7% | Feb 14, 2024 | Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /delete.p... |
| CVE-2024-23789 | HIGH | 8.8 | 1.2% | Feb 14, 2024 | Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent una... |
| CVE-2024-23788 | HIGH | 8.1 | 0.8% | Feb 14, 2024 | Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.... |
| CVE-2024-23783 | HIGH | 8.8 | 0.5% | Feb 14, 2024 | Improper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 ... |
| CVE-2024-24697 | HIGH | 7.8 | 0.3% | Feb 14, 2024 | Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of pr... |
| CVE-2024-25121 | HIGH | 7.1 | 0.5% | Feb 13, 2024 | TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO... |
| CVE-2024-24814 | HIGH | 7.5 | 1.3% | Feb 13, 2024 | mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that imp... |
| CVE-2024-24751 | HIGH | 8.8 | 0.5% | Feb 13, 2024 | sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected... |
| CVE-2024-1354 | HIGH | 8 | 1.7% | Feb 13, 2024 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol... |
| CVE-2024-21420 | HIGH | 8.8 | 1.7% | Feb 13, 2024 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-21412 | HIGH | 8.1 | 95.4% | Feb 13, 2024 | Internet Shortcut Files Security Feature Bypass Vulnerability |
| CVE-2024-21406 | HIGH | 7.5 | 0.9% | Feb 13, 2024 | Windows Printing Service Spoofing Vulnerability |
| CVE-2024-21405 | HIGH | 7 | 0.4% | Feb 13, 2024 | Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability |
| CVE-2024-21404 | HIGH | 7.5 | 2.7% | Feb 13, 2024 | .NET Denial of Service Vulnerability |
| CVE-2024-21402 | HIGH | 7.1 | 0.5% | Feb 13, 2024 | Microsoft Outlook Elevation of Privilege Vulnerability |
| CVE-2024-21396 | HIGH | 7.6 | 1.2% | Feb 13, 2024 | Dynamics 365 Sales Spoofing Vulnerability |
| CVE-2024-21395 | HIGH | 8.2 | 1.1% | Feb 13, 2024 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now