2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-27685 | HIGH | 7.1 | 0.3% | Jun 25, 2025 | SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote attacker to obtain sensi... |
| CVE-2024-51983 | HIGH | 7.5 | 7.5% | Jun 25, 2025 | An unauthenticated attacker who can connect to the Web Services feature (HTTP TCP port 80) can issue a WS-Scan SOAP requ... |
| CVE-2024-51982 | HIGH | 7.5 | 6.8% | Jun 25, 2025 | An unauthenticated attacker who can connect to TCP port 9100 can issue a Printer Job Language (PJL) command that will cr... |
| CVE-2024-51979 | HIGH | 7.2 | 1.1% | Jun 25, 2025 | An authenticated attacker may trigger a stack based buffer overflow by performing a malformed request to either the HTTP... |
| CVE-2024-56917 | HIGH | 7.1 | 0.3% | Jun 24, 2025 | Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode. |
| CVE-2024-4994 | HIGH | 8.1 | 0.4% | Jun 20, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting fr... |
| CVE-2024-4025 | HIGH | 7.5 | 0.5% | Jun 20, 2025 | A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16... |
| CVE-2024-7586 | HIGH | 7.5 | 0.3% | Jun 20, 2025 | An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior... |
| CVE-2024-24916 | HIGH | 7.8 | 1.8% | Jun 19, 2025 | Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution ... |
| CVE-2024-38824 | HIGH | 7.5 | 1.0% | Jun 13, 2025 | Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory... |
| CVE-2024-7562 | HIGH | 7.3 | 0.1% | Jun 12, 2025 | A potential elevated privilege issue has been reported with InstallShield built Standalone MSI setups having multiple In... |
| CVE-2024-9062 | HIGH | 7.8 | 0.1% | Jun 11, 2025 | The Archify application contains a local privilege escalation vulnerability due to insufficient client validation in its... |
| CVE-2024-7457 | HIGH | 7.8 | 0.1% | Jun 11, 2025 | The ws.stash.app.mac.daemon.helper tool contains a vulnerability caused by an incorrect use of macOS’s authorization mod... |
| CVE-2024-43706 | HIGH | 8.8 | 0.3% | Jun 10, 2025 | Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint. |
| CVE-2024-38524 | HIGH | 7.5 | 0.4% | Jun 10, 2025 | GeoServer is an open source server that allows users to share and edit geospatial data. org.geowebcache.GeoWebCacheDispa... |
| CVE-2024-34711 | HIGH | 8.2 | 0.3% | Jun 10, 2025 | GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulne... |
| CVE-2024-29198 | HIGH | 8.2 | 1.9% | Jun 10, 2025 | GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. It poss... |
| CVE-2024-13090 | HIGH | 7.3 | 0.1% | Jun 10, 2025 | A privilege escalation vulnerability may enable a service account to elevate its privileges. The sudo rules configure... |
| CVE-2024-13089 | HIGH | 7.5 | 1.0% | Jun 10, 2025 | An OS command injection vulnerability within the update functionality may allow an authenticated administrator to execut... |
| CVE-2024-13088 | HIGH | 7.8 | 0.2% | Jun 6, 2025 | An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, t... |
| CVE-2024-31127 | HIGH | 7.3 | 0.1% | Jun 4, 2025 | An improper verification of a loaded library in Zscaler Client Connector on Mac < 4.2.0.241 may allow a local attacker t... |
| CVE-2024-54189 | HIGH | 7.8 | 0.3% | Jun 3, 2025 | A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (b... |
| CVE-2024-52561 | HIGH | 7.8 | 0.2% | Jun 3, 2025 | A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (b... |
| CVE-2024-36486 | HIGH | 7.8 | 0.3% | Jun 3, 2025 | A privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Deskto... |
| CVE-2024-53026 | HIGH | 8.2 | 0.3% | Jun 3, 2025 | Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now