2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-58355 | CRITICAL | 9.3 | 0.3% | Jul 23, 2026 | Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking... |
| CVE-2024-58354 | CRITICAL | 9.9 | 0.4% | Jul 23, 2026 | cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Acti... |
| CVE-2024-58353 | CRITICAL | 9.3 | 0.3% | Jul 23, 2026 | Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly ac... |
| CVE-2024-51315 | CRITICAL | 9.8 | 0.2% | Jul 20, 2026 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/Se... |
| CVE-2024-51314 | CRITICAL | 9.8 | 0.2% | Jul 20, 2026 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/se... |
| CVE-2024-51312 | CRITICAL | 9.8 | 0.2% | Jul 20, 2026 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/Se... |
| CVE-2024-51313 | CRITICAL | 9.8 | 0.2% | Jul 20, 2026 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/Se... |
| CVE-2024-51311 | CRITICAL | 9.8 | 0.2% | Jul 20, 2026 | The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/Se... |
| CVE-2024-58366 | CRITICAL | 9 | 0.3% | Jul 18, 2026 | SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when script... |
| CVE-2024-23564 | CRITICAL | 9.1 | — | Jul 17, 2026 | HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obta... |
| CVE-2024-14037 | CRITICAL | 9.8 | — | Jul 2, 2026 | Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote... |
| CVE-2024-58351 | CRITICAL | 9.8 | 0.6% | Jun 20, 2026 | Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig opti... |
| CVE-2024-52488 | CRITICAL | 9.9 | 0.5% | Jun 17, 2026 | Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions. |
| CVE-2024-58349 | CRITICAL | 9.8 | 0.7% | Jun 8, 2026 | WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers ... |
| CVE-2024-58348 | CRITICAL | 9.8 | 0.8% | Jun 8, 2026 | WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticate... |
| CVE-2024-27892 | CRITICAL | 9.6 | 0.3% | Jun 4, 2026 | Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been... |
| CVE-2024-27890 | CRITICAL | 9.6 | 4.4% | Jun 4, 2026 | Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been... |
| CVE-2024-40684 | CRITICAL | 9.8 | 0.4% | May 27, 2026 | IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2,... |
| CVE-2024-51092 | CRITICAL | 9.1 | 6.9% | May 8, 2026 | LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutContr... |
| CVE-2024-46636 | CRITICAL | 9.4 | 0.3% | Apr 27, 2026 | NASA Earth Observing System Data and Information System (EOSDIS) MODAPS v8.1 was discovered to contain a SQL injection v... |
| CVE-2024-2374 | CRITICAL | 9.1 | 0.4% | Apr 16, 2026 | The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the ... |
| CVE-2024-36058 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fail... |
| CVE-2024-36057 | CRITICAL | 9.8 | 1.8% | Apr 7, 2026 | Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code ex... |
| CVE-2024-14034 | CRITICAL | 9.8 | 0.5% | Apr 2, 2026 | Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) managem... |
| CVE-2024-43028 | CRITICAL | 9.8 | 1.5% | Apr 1, 2026 | A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to exe... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now