2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-27480 | CRITICAL | 9.8 | 0.3% | Dec 29, 2025 | givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload. |
| CVE-2024-25183 | HIGH | 7.5 | 0.6% | Dec 29, 2025 | givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php. |
| CVE-2024-25182 | CRITICAL | 9.8 | 0.3% | Dec 29, 2025 | givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php. |
| CVE-2024-30855 | HIGH | 8.8 | 0.2% | Dec 29, 2025 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_act... |
| CVE-2024-25181 | CRITICAL | 9.1 | 0.3% | Dec 29, 2025 | A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSR... |
| CVE-2024-44065 | CRITICAL | 9.8 | 0.4% | Dec 26, 2025 | Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in th... |
| CVE-2024-42718 | MEDIUM | 6.5 | 0.6% | Dec 26, 2025 | A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially craft... |
| CVE-2024-29720 | MEDIUM | 5.5 | 0.2% | Dec 26, 2025 | An issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 allows a local attacker to obtain sensitive information via... |
| CVE-2024-40317 | MEDIUM | 6.1 | 0.2% | Dec 24, 2025 | A reflected cross-site scripting (XSS) vulnerability in MyNET up to v26.08 allows attackers to execute arbitrary code in... |
| CVE-2024-39037 | MEDIUM | 6.5 | 0.2% | Dec 24, 2025 | MyNET up to v26.08.316 was discovered to contain an Unauthenticated SQL Injection vulnerability via the intmenu paramete... |
| CVE-2024-35322 | MEDIUM | 6.1 | 0.2% | Dec 24, 2025 | MyNET up to v26.08 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the ficheiro param... |
| CVE-2024-58335 | MEDIUM | 5 | 0.2% | Dec 24, 2025 | OpenXRechnungToolbox through 2024-10-05-3.0.0 before 6c50e89 allows XXE because the disallow-doctype-decl feature is not... |
| CVE-2024-57521 | CRITICAL | 10 | 0.6% | Dec 23, 2025 | SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the creat... |
| CVE-2024-10398 | — | — | — | Dec 23, 2025 | Rejected reason: This CVE id was assigned but later discarded. |
| CVE-2024-9684 | HIGH | 7.5 | 0.3% | Dec 23, 2025 | FreyrSCADA/IEC-60870-5-104 server v21.06.008 allows remote attackers to cause a denial of service by sending specific me... |
| CVE-2024-24844 | HIGH | 7.5 | 0.2% | Dec 23, 2025 | Missing Authorization vulnerability in IdeaBox Creations PowerPack Pro for Elementor allows Exploiting Incorrectly Confi... |
| CVE-2024-27708 | CRITICAL | 9.6 | 0.5% | Dec 22, 2025 | Iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and before allows a remote attacker t... |
| CVE-2024-25812 | MEDIUM | 6.1 | 0.2% | Dec 22, 2025 | MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the src parameter. |
| CVE-2024-35321 | MEDIUM | 4.3 | 0.3% | Dec 22, 2025 | MyNET up to v26.08 was discovered to contain a Reflected cross-site scripting (XSS) vulnerability via the msgtipo parame... |
| CVE-2024-25814 | MEDIUM | 6.1 | 0.2% | Dec 22, 2025 | MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the msg parameter. |
| CVE-2024-49587 | CRITICAL | 9.1 | 0.3% | Dec 19, 2025 | Glutton V1 service endpoints were exposed without any authentication on Gotham stacks, this could have allowed users tha... |
| CVE-2024-58323 | MEDIUM | 5.4 | 0.1% | Dec 18, 2025 | A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Ch... |
| CVE-2024-58322 | MEDIUM | 5.4 | 0.1% | Dec 18, 2025 | A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious code into shipping... |
| CVE-2024-58321 | MEDIUM | 5.4 | 0.1% | Dec 18, 2025 | A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form v... |
| CVE-2024-58320 | MEDIUM | 6.9 | 0.2% | Dec 18, 2025 | An information disclosure vulnerability in Kentico Xperience allows public users to access sensitive administration inte... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now