2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51317 | MEDIUM | 6.5 | 0.4% | Nov 3, 2025 | An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function |
| CVE-2024-13992 | MEDIUM | 5.4 | 0.5% | Oct 31, 2025 | Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing pag... |
| CVE-2024-14006 | MEDIUM | 6.1 | 0.5% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-su... |
| CVE-2024-14002 | MEDIUM | 5.5 | 1.3% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.4 contain a local file inclusion (LFI) vulnerability via its NagVis integration. An... |
| CVE-2024-14001 | MEDIUM | 5.4 | 0.6% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Executive Summary Report com... |
| CVE-2024-14000 | MEDIUM | 5.4 | 0.6% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Capacity Planning Report com... |
| CVE-2024-13993 | MEDIUM | 6.1 | 0.8% | Oct 30, 2025 | Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) via the login page whe... |
| CVE-2024-58269 | MEDIUM | 4.3 | 0.3% | Oct 29, 2025 | A vulnerability has been identified in Rancher Manager, where sensitive information, including secret data, cluster imp... |
| CVE-2024-45161 | MEDIUM | 4.6 | 0.1% | Oct 29, 2025 | A CSRF issue was discovered in the administrative web GUI in Blu-Castle BCUM221E 1.0.0P220507. This can be exploited via... |
| CVE-2024-31573 | MEDIUM | 4 | 0.2% | Oct 17, 2025 | XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (us... |
| CVE-2024-42192 | MEDIUM | 5.5 | 0.2% | Oct 16, 2025 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access... |
| CVE-2024-47569 | MEDIUM | 4.3 | 0.4% | Oct 14, 2025 | A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7... |
| CVE-2024-26008 | MEDIUM | 5.3 | 0.4% | Oct 14, 2025 | An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 a... |
| CVE-2024-44088 | MEDIUM | 6.1 | 0.6% | Oct 14, 2025 | Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability all... |
| CVE-2024-57494 | MEDIUM | 6.5 | 0.3% | Oct 1, 2025 | Cross Site Scripting vulnerability in Neto E-Commerce CMS v.6.313.0 through v.6.3115 allows a remote attacker to escalat... |
| CVE-2024-5200 | MEDIUM | 4.8 | 0.2% | Sep 29, 2025 | The Postie WordPress plugin before 1.9.71 does not sanitise and escape some of its settings, which could allow high priv... |
| CVE-2024-58241 | MEDIUM | 5.5 | 0.1% | Sep 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Disable works on hci_unregiste... |
| CVE-2024-21935 | MEDIUM | 5 | 0.2% | Sep 23, 2025 | Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to manipulate R... |
| CVE-2024-21927 | MEDIUM | 5 | 0.3% | Sep 23, 2025 | Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to use certain ... |
| CVE-2024-6429 | MEDIUM | 4.3 | 0.2% | Sep 23, 2025 | A content spoofing vulnerability exists in multiple WSO2 products due to improper error message handling. Under certain ... |
| CVE-2024-4598 | MEDIUM | 6.5 | 0.3% | Sep 23, 2025 | An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich me... |
| CVE-2024-25011 | MEDIUM | 5.3 | 0.3% | Sep 18, 2025 | Ericsson Catalog Manager and Ericsson Order Care APIs do not have authentication enabled by default. Authentication chec... |
| CVE-2024-12796 | MEDIUM | 5.3 | 0.2% | Sep 16, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Holistic IT... |
| CVE-2024-45433 | MEDIUM | 6.5 | 0.5% | Sep 12, 2025 | OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Incorrect Control Flow Scoping. The specific flaw exists within the B... |
| CVE-2024-45431 | MEDIUM | 5.3 | 4.4% | Sep 12, 2025 | OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Improper Input Validation. The specific flaw exists within the BlueSD... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now