2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12925 | HIGH | 7.3 | 0.1% | Sep 1, 2025 | Improper Validation of Certificate with Host Mismatch vulnerability in Akınsoft QR Menü allows HTTP Response Splitting. ... |
| CVE-2024-32589 | HIGH | 7.1 | 0.2% | Aug 31, 2025 | Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager ... |
| CVE-2024-46917 | HIGH | 8.1 | 0.2% | Aug 29, 2025 | Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR01 does not validate file attributes or the contents of /root dur... |
| CVE-2024-46916 | HIGH | 8.1 | 0.3% | Aug 29, 2025 | Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical sys... |
| CVE-2024-13986 | HIGH | 8.8 | 1.6% | Aug 28, 2025 | Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload an... |
| CVE-2024-58240 | HIGH | 7.8 | 0.2% | Aug 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: tls: separate no-async decryption request handling ... |
| CVE-2024-13807 | HIGH | 7.5 | 0.4% | Aug 28, 2025 | The Xagio SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,... |
| CVE-2024-13982 | HIGH | 8.7 | 1.0% | Aug 27, 2025 | SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON Communications, contains an ar... |
| CVE-2024-37777 | HIGH | 8.8 | 0.5% | Aug 27, 2025 | O2OA v9.0.3 was discovered to contain a remote code execution (RCE) vulnerability via the mainOutput() function. |
| CVE-2024-47853 | HIGH | 8.8 | 0.3% | Aug 26, 2025 | An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases w... |
| CVE-2024-48988 | HIGH | 7.6 | 0.6% | Aug 22, 2025 | SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users... |
| CVE-2024-53494 | HIGH | 7.5 | 0.3% | Aug 22, 2025 | Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive compone... |
| CVE-2024-56179 | HIGH | 7.8 | 0.4% | Aug 22, 2025 | In MindManager Windows versions prior to 24.1.150, attackers could potentially write to unexpected directories in victim... |
| CVE-2024-50641 | HIGH | 8.1 | 0.4% | Aug 21, 2025 | An authentication bypass vulnerability in PandoraNext-TokensTool v0.6.8 and before. An attacker can exploit this vulnera... |
| CVE-2024-57152 | HIGH | 7.5 | 0.3% | Aug 20, 2025 | Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components wit... |
| CVE-2024-53495 | HIGH | 7.5 | 0.3% | Aug 20, 2025 | Incorrect access control in the preHandle function of my-site v1.0.2.RELEASE allows attackers to access sensitive compon... |
| CVE-2024-57491 | HIGH | 8.8 | 0.3% | Aug 20, 2025 | Authentication Bypass vulnerability in jobx up to v1.0.1-RELEASE allows an attacker can exploit this vulnerability to ac... |
| CVE-2024-49827 | HIGH | 7.5 | 0.2% | Aug 18, 2025 | IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to excessive data exposure, allowing attackers to access sensitiv... |
| CVE-2024-12612 | HIGH | 7.5 | 0.4% | Aug 16, 2025 | The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via several parameters ac... |
| CVE-2024-53946 | HIGH | 8.8 | 0.6% | Aug 14, 2025 | The KuWFi 4G LTE AC900 router 1.0.13 is vulnerable to Cross-Site Request Forgery (CSRF) on its web management interface.... |
| CVE-2024-53945 | HIGH | 8.8 | 19.0% | Aug 14, 2025 | The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints /goform/formMultiApnSe... |
| CVE-2024-7402 | HIGH | 7 | 0.1% | Aug 14, 2025 | Netskope has identified a potential gap in its agent (Netskope Client) in which a malicious insider can potentially tamp... |
| CVE-2024-5477 | HIGH | 7.3 | 0.2% | Aug 13, 2025 | A potential security vulnerability has been identified in the System BIOS for some HP PC products which may allow escala... |
| CVE-2024-26009 | HIGH | 8.1 | 0.6% | Aug 12, 2025 | An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.... |
| CVE-2024-54678 | HIGH | 8.6 | 0.2% | Aug 12, 2025 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now