2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-14044 | MEDIUM | 6.3 | — | Aug 12, 2026 | A vulnerability was identified in Open5GS up to 2.7.1. This issue affects the function pcrf_rx_aar_cb of the file src/pc... |
| CVE-2024-14043 | MEDIUM | 6.3 | — | Aug 12, 2026 | A vulnerability was determined in Open5GS up to 2.7.1. This vulnerability affects the function mme_s6a_subscription_data... |
| CVE-2024-14042 | MEDIUM | 6.3 | — | Aug 11, 2026 | A vulnerability was found in Open5GS up to 2.7.1. This affects the function hss_ogs_diam_s6a_air_cb/hss_ogs_diam_s6a_ulr... |
| CVE-2024-6541 | MEDIUM | 6.8 | 0.3% | Aug 6, 2026 | The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dy... |
| CVE-2024-39024 | HIGH | 8.8 | 0.4% | Aug 6, 2026 | In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution. |
| CVE-2024-8995 | MEDIUM | 4.9 | 0.1% | Aug 6, 2026 | Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This a... |
| CVE-2024-6832 | HIGH | 7.5 | 0.3% | Aug 6, 2026 | The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not mainta... |
| CVE-2024-10302 | MEDIUM | 5.8 | 0.2% | Aug 6, 2026 | The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allo... |
| CVE-2024-40683 | MEDIUM | 6.3 | — | Jul 30, 2026 | IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2,... |
| CVE-2024-25039 | HIGH | 7.5 | 0.3% | Jul 30, 2026 | IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1... |
| CVE-2024-14041 | HIGH | 8.2 | 0.3% | Jul 28, 2026 | In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polyno... |
| CVE-2024-14040 | HIGH | 7.8 | 0.1% | Jul 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Increase weight to u16 In CLOS netwo... |
| CVE-2024-58355 | CRITICAL | 9.3 | 0.3% | Jul 23, 2026 | Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking... |
| CVE-2024-58354 | CRITICAL | 9.9 | 0.4% | Jul 23, 2026 | cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Acti... |
| CVE-2024-58353 | CRITICAL | 9.3 | 0.3% | Jul 23, 2026 | Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly ac... |
| CVE-2024-58330 | HIGH | 7.5 | 0.5% | Jul 23, 2026 | A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to ret... |
| CVE-2024-58023 | HIGH | 8.4 | 0.1% | Jul 23, 2026 | Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive inform... |
| CVE-2024-5300 | MEDIUM | 5.6 | — | Jul 21, 2026 | An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configura... |
| CVE-2024-51316 | HIGH | 7.5 | 0.2% | Jul 20, 2026 | The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /g... |
| CVE-2024-51315 | CRITICAL | 9.8 | 0.2% | Jul 20, 2026 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/Se... |
| CVE-2024-51314 | CRITICAL | 9.8 | 0.2% | Jul 20, 2026 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/se... |
| CVE-2024-51312 | CRITICAL | 9.8 | 0.2% | Jul 20, 2026 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/Se... |
| CVE-2024-51313 | CRITICAL | 9.8 | 0.2% | Jul 20, 2026 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/Se... |
| CVE-2024-51311 | CRITICAL | 9.8 | 0.2% | Jul 20, 2026 | The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/Se... |
| CVE-2024-58370 | MEDIUM | 6.5 | 0.3% | Jul 18, 2026 | SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements includin... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now