2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-26293 | HIGH | 8.7 | 0.4% | Jul 14, 2025 | The Avid Nexis Agent uses a vulnerable gSOAP version. An undocumented vulnerability impacting gSOAP v2.8 makes the appli... |
| CVE-2024-26292 | HIGH | 7.1 | 0.4% | Jul 14, 2025 | An authenticated Arbitrary File Deletion vulnerability enables an attacker to delete critical files. This issue affects ... |
| CVE-2024-26291 | HIGH | 8.7 | 1.1% | Jul 14, 2025 | An Unauthenticated Arbitrary File Read vulnerability affects the Agent when installed on a system. The parameter filenam... |
| CVE-2024-58258 | HIGH | 7.2 | 13.2% | Jul 13, 2025 | SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can... |
| CVE-2024-41169 | HIGH | 7.5 | 0.6% | Jul 12, 2025 | The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, in... |
| CVE-2024-47252 | HIGH | 7.5 | 0.7% | Jul 10, 2025 | Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/... |
| CVE-2024-43394 | HIGH | 7.5 | 1.1% | Jul 10, 2025 | Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a maliciou... |
| CVE-2024-43204 | HIGH | 7.5 | 0.8% | Jul 10, 2025 | SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled ... |
| CVE-2024-42516 | HIGH | 7.5 | 0.7% | Jul 10, 2025 | HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type respons... |
| CVE-2024-52965 | HIGH | 7.2 | 0.3% | Jul 8, 2025 | A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0... |
| CVE-2024-53009 | HIGH | 7.8 | 0.1% | Jul 8, 2025 | Memory corruption while operating the mailbox in Automotive. |
| CVE-2024-31854 | HIGH | 8.1 | 0.2% | Jul 8, 2025 | A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connect... |
| CVE-2024-31853 | HIGH | 8.1 | 0.2% | Jul 8, 2025 | A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connect... |
| CVE-2024-25177 | HIGH | 7.5 | 0.5% | Jul 7, 2025 | LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which l... |
| CVE-2024-43334 | HIGH | 7.1 | 0.2% | Jul 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gavias Zilom zilom... |
| CVE-2024-35164 | HIGH | 7.5 | 0.4% | Jul 2, 2025 | The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers... |
| CVE-2024-13451 | HIGH | 7.5 | 0.3% | Jul 2, 2025 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil... |
| CVE-2024-49365 | HIGH | 8.1 | 0.2% | Jul 1, 2025 | tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a malicious JSON-stringifyable message can... |
| CVE-2024-49364 | HIGH | 8.1 | 0.3% | Jul 1, 2025 | tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a private key can be extracted on signing ... |
| CVE-2024-46992 | HIGH | 7.8 | 0.1% | Jul 1, 2025 | Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Fro... |
| CVE-2024-53621 | HIGH | 7.5 | 0.4% | Jun 30, 2025 | A buffer overflow in the formSetCfm() function of Tenda AC1206 1200M 11ac US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 allow... |
| CVE-2024-8419 | HIGH | 7.5 | 0.4% | Jun 30, 2025 | The endpoint hosts a script that allows an unauthorized remote attacker to put the system in a fail-safe state over the ... |
| CVE-2024-24915 | HIGH | 7.2 | 0.2% | Jun 29, 2025 | Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump ... |
| CVE-2024-52928 | HIGH | 8.3 | 0.4% | Jun 26, 2025 | Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permi... |
| CVE-2024-6174 | HIGH | 8.8 | 0.2% | Jun 26, 2025 | When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To preven... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now