2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53494 | HIGH | 7.5 | 0.3% | Aug 22, 2025 | Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive compone... |
| CVE-2024-56179 | HIGH | 7.8 | 0.4% | Aug 22, 2025 | In MindManager Windows versions prior to 24.1.150, attackers could potentially write to unexpected directories in victim... |
| CVE-2024-50641 | HIGH | 8.1 | 0.4% | Aug 21, 2025 | An authentication bypass vulnerability in PandoraNext-TokensTool v0.6.8 and before. An attacker can exploit this vulnera... |
| CVE-2024-57152 | HIGH | 7.5 | 0.3% | Aug 20, 2025 | Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components wit... |
| CVE-2024-53495 | HIGH | 7.5 | 0.3% | Aug 20, 2025 | Incorrect access control in the preHandle function of my-site v1.0.2.RELEASE allows attackers to access sensitive compon... |
| CVE-2024-57491 | HIGH | 8.8 | 0.3% | Aug 20, 2025 | Authentication Bypass vulnerability in jobx up to v1.0.1-RELEASE allows an attacker can exploit this vulnerability to ac... |
| CVE-2024-49827 | HIGH | 7.5 | 0.2% | Aug 18, 2025 | IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to excessive data exposure, allowing attackers to access sensitiv... |
| CVE-2024-12612 | HIGH | 7.5 | 0.4% | Aug 16, 2025 | The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via several parameters ac... |
| CVE-2024-53946 | HIGH | 8.8 | 0.6% | Aug 14, 2025 | The KuWFi 4G LTE AC900 router 1.0.13 is vulnerable to Cross-Site Request Forgery (CSRF) on its web management interface.... |
| CVE-2024-53945 | HIGH | 8.8 | 19.0% | Aug 14, 2025 | The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints /goform/formMultiApnSe... |
| CVE-2024-7402 | HIGH | 7 | 0.1% | Aug 14, 2025 | Netskope has identified a potential gap in its agent (Netskope Client) in which a malicious insider can potentially tamp... |
| CVE-2024-5477 | HIGH | 7.3 | 0.2% | Aug 13, 2025 | A potential security vulnerability has been identified in the System BIOS for some HP PC products which may allow escala... |
| CVE-2024-26009 | HIGH | 8.1 | 0.6% | Aug 12, 2025 | An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.... |
| CVE-2024-54678 | HIGH | 8.6 | 0.2% | Aug 12, 2025 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC... |
| CVE-2024-52504 | HIGH | 8.7 | 0.4% | Aug 12, 2025 | A vulnerability has been identified in SIPROTEC 4 6MD61 (All versions), SIPROTEC 4 6MD63 (All versions), SIPROTEC 4 6MD6... |
| CVE-2024-41985 | HIGH | 7.3 | 0.2% | Aug 12, 2025 | A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au... |
| CVE-2024-41979 | HIGH | 8 | 0.2% | Aug 12, 2025 | A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au... |
| CVE-2024-58256 | HIGH | 7.8 | 0.3% | Aug 8, 2025 | EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary com... |
| CVE-2024-56339 | HIGH | 7.5 | 0.4% | Aug 7, 2025 | IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a re... |
| CVE-2024-48916 | HIGH | 8.1 | 0.2% | Jul 30, 2025 | Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an ... |
| CVE-2024-45955 | HIGH | 7.3 | 0.4% | Jul 30, 2025 | Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter. |
| CVE-2024-51473 | HIGH | 7.5 | 0.3% | Jul 29, 2025 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 1... |
| CVE-2024-49828 | HIGH | 7.5 | 0.3% | Jul 29, 2025 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 1... |
| CVE-2024-42655 | HIGH | 8.8 | 0.3% | Jul 29, 2025 | An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system ... |
| CVE-2024-42651 | HIGH | 7.5 | 0.4% | Jul 29, 2025 | NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vuln... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now