2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-58388 | HIGH | 7.5 | — | Oct 1, 2026 | Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability t... |
| CVE-2024-58387 | HIGH | 7.5 | 0.7% | Sep 30, 2026 | Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint th... |
| CVE-2024-31027 | MEDIUM | 5.4 | — | Sep 29, 2026 | Cross Site Scripting vulnerability in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote att... |
| CVE-2024-31026 | CRITICAL | 9.8 | 0.2% | Sep 29, 2026 | An issue in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote attacker to execute arbitrary... |
| CVE-2024-58386 | MEDIUM | 6.5 | 0.4% | Sep 28, 2026 | ZoneMinder versions 1.37.0 before 1.38.0 contain a path traversal vulnerability in the files view that allows authentica... |
| CVE-2024-42002 | HIGH | 8.4 | 0.2% | Sep 28, 2026 | A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool... |
| CVE-2024-56344 | MEDIUM | 5.9 | 0.2% | Sep 18, 2026 | IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain se... |
| CVE-2024-38639 | MEDIUM | 4.8 | 0.2% | Sep 18, 2026 | An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the ... |
| CVE-2024-27123 | MEDIUM | 5.2 | 0.1% | Sep 18, 2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent. The local attackers can then exploit t... |
| CVE-2024-11222 | MEDIUM | 6.4 | 0.2% | Sep 16, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 1... |
| CVE-2024-58385 | CRITICAL | 9.8 | 0.4% | Sep 15, 2026 | Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpo... |
| CVE-2024-58384 | MEDIUM | 5.4 | 0.2% | Sep 15, 2026 | Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return... |
| CVE-2024-14029 | HIGH | 7.5 | 0.4% | Sep 15, 2026 | Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body a... |
| CVE-2024-58383 | HIGH | 7.3 | 0.1% | Sep 14, 2026 | Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via ... |
| CVE-2024-23176 | MEDIUM | 5.4 | 0.2% | Sep 14, 2026 | An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss... |
| CVE-2024-53922 | MEDIUM | 5.7 | 0.2% | Sep 14, 2026 | An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. L... |
| CVE-2024-12145 | MEDIUM | 4.3 | — | Sep 11, 2026 | The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi... |
| CVE-2024-58382 | HIGH | 7.5 | — | Sep 9, 2026 | league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allo... |
| CVE-2024-58381 | HIGH | 7.5 | 0.4% | Sep 9, 2026 | PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote... |
| CVE-2024-58380 | MEDIUM | 6.5 | 0.4% | Sep 9, 2026 | PocketMine-MP versions before 5.11.2 contain a denial of service vulnerability in BookEditPacket handling that crashes t... |
| CVE-2024-11080 | CRITICAL | 9.8 | 0.4% | Sep 5, 2026 | The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in... |
| CVE-2024-7956 | HIGH | 7.6 | 0.3% | Sep 2, 2026 | A vulnerability exists in the affected products that allows a threat actor to gain access to user’s projects. To exploit... |
| CVE-2024-3773 | MEDIUM | 5.9 | 0.1% | Sep 2, 2026 | The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes b... |
| CVE-2024-35585 | HIGH | 8.6 | 0.3% | Sep 2, 2026 | Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication. |
| CVE-2024-7953 | HIGH | 8.7 | — | Sep 1, 2026 | A vulnerability exists in the affected products that allows a threat actor to create a project and become the administra... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now