2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43334 | HIGH | 7.1 | 0.2% | Jul 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gavias Zilom zilom... |
| CVE-2024-35164 | HIGH | 7.5 | 0.4% | Jul 2, 2025 | The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers... |
| CVE-2024-13451 | HIGH | 7.5 | 0.3% | Jul 2, 2025 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil... |
| CVE-2024-49365 | HIGH | 8.1 | 0.2% | Jul 1, 2025 | tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a malicious JSON-stringifyable message can... |
| CVE-2024-49364 | HIGH | 8.1 | 0.3% | Jul 1, 2025 | tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a private key can be extracted on signing ... |
| CVE-2024-46992 | HIGH | 7.8 | 0.1% | Jul 1, 2025 | Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Fro... |
| CVE-2024-53621 | HIGH | 7.5 | 0.4% | Jun 30, 2025 | A buffer overflow in the formSetCfm() function of Tenda AC1206 1200M 11ac US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 allow... |
| CVE-2024-8419 | HIGH | 7.5 | 0.4% | Jun 30, 2025 | The endpoint hosts a script that allows an unauthorized remote attacker to put the system in a fail-safe state over the ... |
| CVE-2024-24915 | HIGH | 7.2 | 0.2% | Jun 29, 2025 | Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump ... |
| CVE-2024-52928 | HIGH | 8.3 | 0.4% | Jun 26, 2025 | Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permi... |
| CVE-2024-6174 | HIGH | 8.8 | 0.2% | Jun 26, 2025 | When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To preven... |
| CVE-2024-27685 | HIGH | 7.1 | 0.3% | Jun 25, 2025 | SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote attacker to obtain sensi... |
| CVE-2024-51983 | HIGH | 7.5 | 7.5% | Jun 25, 2025 | An unauthenticated attacker who can connect to the Web Services feature (HTTP TCP port 80) can issue a WS-Scan SOAP requ... |
| CVE-2024-51982 | HIGH | 7.5 | 6.8% | Jun 25, 2025 | An unauthenticated attacker who can connect to TCP port 9100 can issue a Printer Job Language (PJL) command that will cr... |
| CVE-2024-51979 | HIGH | 7.2 | 1.1% | Jun 25, 2025 | An authenticated attacker may trigger a stack based buffer overflow by performing a malformed request to either the HTTP... |
| CVE-2024-56917 | HIGH | 7.1 | 0.3% | Jun 24, 2025 | Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode. |
| CVE-2024-4994 | HIGH | 8.1 | 0.4% | Jun 20, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting fr... |
| CVE-2024-4025 | HIGH | 7.5 | 0.5% | Jun 20, 2025 | A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16... |
| CVE-2024-7586 | HIGH | 7.5 | 0.3% | Jun 20, 2025 | An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior... |
| CVE-2024-24916 | HIGH | 7.8 | 1.8% | Jun 19, 2025 | Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution ... |
| CVE-2024-38824 | HIGH | 7.5 | 1.0% | Jun 13, 2025 | Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory... |
| CVE-2024-7562 | HIGH | 7.3 | 0.1% | Jun 12, 2025 | A potential elevated privilege issue has been reported with InstallShield built Standalone MSI setups having multiple In... |
| CVE-2024-9062 | HIGH | 7.8 | 0.1% | Jun 11, 2025 | The Archify application contains a local privilege escalation vulnerability due to insufficient client validation in its... |
| CVE-2024-7457 | HIGH | 7.8 | 0.1% | Jun 11, 2025 | The ws.stash.app.mac.daemon.helper tool contains a vulnerability caused by an incorrect use of macOS’s authorization mod... |
| CVE-2024-43706 | HIGH | 8.8 | 0.3% | Jun 10, 2025 | Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now