2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49722 | MEDIUM | 5.5 | 0.1% | Sep 2, 2025 | In showAvatarPicker of EditUserPhotoController.java, there is a possible cross user image leak due to a confused deputy.... |
| CVE-2024-51423 | MEDIUM | 6.1 | 0.3% | Sep 2, 2025 | Cross Site Scripting vulnerability in Infor Global HR GHR v.11.23.03.00.21 and before allows a remote attacker to execut... |
| CVE-2024-48705 | MEDIUM | 6.5 | 3.6% | Sep 2, 2025 | Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication ... |
| CVE-2024-12974 | MEDIUM | 4.3 | 0.2% | Sep 2, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft Pr... |
| CVE-2024-12973 | MEDIUM | 4.7 | 0.1% | Sep 2, 2025 | Origin Validation Error vulnerability in Akinsoft OctoCloud allows HTTP Response Splitting, CAPEC - 87 - Forceful Browsi... |
| CVE-2024-12972 | MEDIUM | 4.3 | 0.2% | Sep 2, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft Oc... |
| CVE-2024-12924 | MEDIUM | 6.3 | 0.2% | Sep 1, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Akınsoft QR Menü allows Forceful Browsing, Phishing... |
| CVE-2024-12914 | MEDIUM | 4.3 | 0.2% | Sep 1, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akınsoft QR... |
| CVE-2024-12923 | MEDIUM | 5.4 | 0.2% | Aug 29, 2025 | A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If a remote attacker gains a user ... |
| CVE-2024-13987 | MEDIUM | 5.9 | 0.3% | Aug 29, 2025 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Synology RADIUS Se... |
| CVE-2024-54568 | MEDIUM | 4.3 | 0.2% | Aug 29, 2025 | The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. Parsing a maliciously ... |
| CVE-2024-54554 | MEDIUM | 5.5 | 0.2% | Aug 29, 2025 | This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be ab... |
| CVE-2024-48908 | MEDIUM | 6.9 | 0.4% | Aug 28, 2025 | lychee link checking action checks links in Markdown, HTML, and text files using lychee. Prior to version 2.0.2, there i... |
| CVE-2024-49790 | MEDIUM | 5.4 | 0.2% | Aug 28, 2025 | IBM Watson Studio on Cloud Pak for Data 4.0 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows an ... |
| CVE-2024-9648 | MEDIUM | 6.1 | 0.2% | Aug 28, 2025 | The WP ULike Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation i... |
| CVE-2024-49740 | MEDIUM | 5.5 | 0.1% | Aug 26, 2025 | In multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to local denial of ser... |
| CVE-2024-47192 | MEDIUM | 5.3 | 0.1% | Aug 26, 2025 | An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker ... |
| CVE-2024-35203 | MEDIUM | 6.1 | 0.2% | Aug 26, 2025 | Mahara before 22.10.6, 23.04.6, and 24.04.1 allows cross-site scripting (XSS) via a file, with JavaScript code as part o... |
| CVE-2024-45753 | MEDIUM | 6.1 | 0.2% | Aug 26, 2025 | In Mahara 23.04.8 and 24.04.4, the external RSS feed block can cause XSS if the external feed XML has a malicious value ... |
| CVE-2024-8860 | MEDIUM | 4.3 | 0.2% | Aug 26, 2025 | The Tourfic plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on... |
| CVE-2024-46413 | MEDIUM | 5.1 | 0.3% | Aug 25, 2025 | Rebuild v3.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the type parameter in the com.rebuild.... |
| CVE-2024-46412 | MEDIUM | 6.5 | 0.4% | Aug 25, 2025 | Incorrect access control in the prehandle function of Rebuild v3.7.7 allows attackers to bypass authentication via a cra... |
| CVE-2024-39923 | MEDIUM | 6.1 | 0.2% | Aug 25, 2025 | An issue was discovered in Mahara 24.04 before 24.04.2 and 23.04 before 23.04.7. The About, Contact, and Help footer lin... |
| CVE-2024-58239 | MEDIUM | 5.5 | 0.2% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: tls: stop recv() if initial process_rx_list gave us... |
| CVE-2024-39954 | MEDIUM | 6.3 | 0.4% | Aug 20, 2025 | CWE-918 Server-Side Request Forgery (SSRF) in eventmesh-runtime module in WebhookUtil.java on windows\linux\mac os e.g. ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now