2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52964 | MEDIUM | 6.5 | 0.6% | Aug 12, 2025 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For... |
| CVE-2024-48892 | MEDIUM | 4.9 | 0.4% | Aug 12, 2025 | A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all vers... |
| CVE-2024-40588 | MEDIUM | 4.4 | 0.2% | Aug 12, 2025 | Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiC... |
| CVE-2024-33607 | MEDIUM | 5.6 | 0.1% | Aug 12, 2025 | Out-of-bounds read in some Intel(R) TDX module software before version TDX_1.5.07.00.774 may allow an authenticated user... |
| CVE-2024-38805 | MEDIUM | 6.3 | 0.2% | Aug 12, 2025 | EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A succe... |
| CVE-2024-41986 | MEDIUM | 6.8 | 0.1% | Aug 12, 2025 | A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au... |
| CVE-2024-41983 | MEDIUM | 4.3 | 0.2% | Aug 12, 2025 | A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au... |
| CVE-2024-41982 | MEDIUM | 5.7 | 0.1% | Aug 12, 2025 | A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au... |
| CVE-2024-41980 | MEDIUM | 5.7 | 0.1% | Aug 12, 2025 | A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au... |
| CVE-2024-58238 | MEDIUM | 5.5 | 0.1% | Aug 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btnxpuart: Resolve TX timeout error in p... |
| CVE-2024-58257 | MEDIUM | 6.7 | 0.4% | Aug 8, 2025 | EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary com... |
| CVE-2024-58255 | MEDIUM | 6.7 | 0.3% | Aug 8, 2025 | EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary com... |
| CVE-2024-42048 | MEDIUM | 6.5 | 0.4% | Aug 7, 2025 | OpenOrange Business Framework version 1.15.5 installs to a directory with overly permissive access control, allowing all... |
| CVE-2024-55401 | MEDIUM | 6.5 | 0.5% | Aug 7, 2025 | An issue in 4C Strategies Exonaut before v22.4 allows attackers to execute a directory traversal. |
| CVE-2024-52680 | MEDIUM | 6.1 | 0.2% | Aug 7, 2025 | EyouCMS 1.6.7 is vulnerable to Cross Site Scripting (XSS) in /login.php?m=admin&c=System&a=web&lang=cn. |
| CVE-2024-55402 | MEDIUM | 5.3 | 0.3% | Aug 6, 2025 | 4C Strategies Exonaut before v22.4 was discovered to contain an access control issue. |
| CVE-2024-55399 | MEDIUM | 6.5 | 0.3% | Aug 6, 2025 | 4C Strategies Exonaut before v21.6.2.1-1 was discovered to contain a Server-Side Request Forgery (SSRF). |
| CVE-2024-55398 | MEDIUM | 6.5 | 0.3% | Aug 6, 2025 | 4C Strategies Exonaut before v22.4 was discovered to contain insecure permissions. |
| CVE-2024-52885 | MEDIUM | 5.4 | 0.4% | Aug 6, 2025 | The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticat... |
| CVE-2024-52890 | MEDIUM | 6.1 | 0.2% | Aug 5, 2025 | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.03 could be susceptible to cross-site scripting due to n... |
| CVE-2024-45183 | MEDIUM | 6.5 | 0.2% | Aug 4, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, and 2400. A lack of a JPE... |
| CVE-2024-51775 | MEDIUM | 5.3 | 0.2% | Aug 3, 2025 | Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server... |
| CVE-2024-52279 | MEDIUM | 5.3 | 0.9% | Aug 3, 2025 | Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not ac... |
| CVE-2024-41177 | MEDIUM | 6.1 | 0.6% | Aug 3, 2025 | Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: befo... |
| CVE-2024-34327 | MEDIUM | 6.5 | 0.3% | Jul 31, 2025 | Sielox AnyWare v2.1.2 was discovered to contain a SQL injection vulnerability via the email address field of the passwor... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now