2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-27779 | MEDIUM | 6.7 | 0.5% | Jul 18, 2025 | An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version... |
| CVE-2024-42912 | MEDIUM | 5.4 | 0.2% | Jul 16, 2025 | A cross-site scripting (XSS) vulnerability in META-INF Kft. Email This Issue (Data Center) before 9.13.0-GA allows attac... |
| CVE-2024-9343 | MEDIUM | 6.1 | 0.2% | Jul 16, 2025 | In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Con... |
| CVE-2024-10032 | MEDIUM | 5.4 | 0.2% | Jul 16, 2025 | In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Con... |
| CVE-2024-10031 | MEDIUM | 5.4 | 0.2% | Jul 16, 2025 | In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configur... |
| CVE-2024-10029 | MEDIUM | 6.1 | 0.2% | Jul 16, 2025 | In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration ... |
| CVE-2024-42649 | MEDIUM | 6.5 | 0.3% | Jul 14, 2025 | NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a ... |
| CVE-2024-42648 | MEDIUM | 6.5 | 0.3% | Jul 14, 2025 | NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via ... |
| CVE-2024-38648 | MEDIUM | 5.7 | 0.6% | Jul 12, 2025 | A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensit... |
| CVE-2024-47065 | MEDIUM | 6.5 | 0.2% | Jul 11, 2025 | Meshtastic is an open source mesh networking solution. Prior to 2.5.1, traceroute responses from the remote node are not... |
| CVE-2024-37524 | MEDIUM | 5.3 | 0.3% | Jul 10, 2025 | IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain sensitive information when a de... |
| CVE-2024-36697 | MEDIUM | 6.1 | 0.2% | Jul 10, 2025 | A cross-site scripting (XSS) vulnerability in the Admin Login page of Allworx System Software v9.1.9.12 allows attackers... |
| CVE-2024-7650 | MEDIUM | 6.3 | 0.3% | Jul 10, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Directory Services allows Remote Co... |
| CVE-2024-56468 | MEDIUM | 6.5 | 0.3% | Jul 8, 2025 | IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 could allow a remote user to cause a denial of service ... |
| CVE-2024-49784 | MEDIUM | 6.5 | 0.1% | Jul 8, 2025 | IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in storage of encrypted data with AE... |
| CVE-2024-49783 | MEDIUM | 6.5 | 0.3% | Jul 8, 2025 | IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in storage of encrypted data. If a... |
| CVE-2024-36357 | MEDIUM | 5.6 | 0.3% | Jul 8, 2025 | A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potenti... |
| CVE-2024-36350 | MEDIUM | 5.6 | 0.4% | Jul 8, 2025 | A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, pot... |
| CVE-2024-55599 | MEDIUM | 5.3 | 0.3% | Jul 8, 2025 | An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 an... |
| CVE-2024-43190 | MEDIUM | 5.9 | 0.3% | Jul 7, 2025 | IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to ob... |
| CVE-2024-37658 | MEDIUM | 6.1 | 0.2% | Jul 7, 2025 | An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the bb... |
| CVE-2024-37657 | MEDIUM | 6.1 | 0.2% | Jul 7, 2025 | An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via thebbs... |
| CVE-2024-37656 | MEDIUM | 6.1 | 0.5% | Jul 7, 2025 | An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the in... |
| CVE-2024-9453 | MEDIUM | 6.5 | 0.3% | Jul 4, 2025 | A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially c... |
| CVE-2024-11937 | MEDIUM | 5.4 | 0.2% | Jul 4, 2025 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's link... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now