2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-30516 | HIGH | 7.5 | 0.2% | Jan 5, 2026 | Improper Validation of Specified Quantity in Input vulnerability in SaasProject Booking Package allows Accessing Functio... |
| CVE-2024-30461 | HIGH | 7.1 | 0.1% | Jan 5, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tumult Inc ... |
| CVE-2024-23511 | MEDIUM | 6.5 | 0.1% | Jan 5, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in POSIMYTH Th... |
| CVE-2024-55374 | MEDIUM | 5.3 | 0.3% | Jan 2, 2026 | REDCap 14.3.13 allows an attacker to enumerate usernames due to an observable discrepancy between login attempts. |
| CVE-2024-58338 | CRITICAL | 10 | 0.7% | Dec 30, 2025 | Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed ... |
| CVE-2024-58337 | HIGH | 8.7 | 0.2% | Dec 30, 2025 | Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to... |
| CVE-2024-58336 | HIGH | 8.7 | 0.3% | Dec 30, 2025 | Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video s... |
| CVE-2024-58315 | HIGH | 7.8 | 0.2% | Dec 30, 2025 | Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that allows local non-privileged users to pote... |
| CVE-2024-58247 | — | — | — | Dec 30, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w... |
| CVE-2024-58246 | — | — | — | Dec 30, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w... |
| CVE-2024-58245 | — | — | — | Dec 30, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w... |
| CVE-2024-58244 | — | — | — | Dec 30, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w... |
| CVE-2024-58243 | — | — | — | Dec 30, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w... |
| CVE-2024-58242 | — | — | — | Dec 30, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w... |
| CVE-2024-27480 | CRITICAL | 9.8 | 0.3% | Dec 29, 2025 | givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload. |
| CVE-2024-25183 | HIGH | 7.5 | 0.6% | Dec 29, 2025 | givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php. |
| CVE-2024-25182 | CRITICAL | 9.8 | 0.3% | Dec 29, 2025 | givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php. |
| CVE-2024-30855 | HIGH | 8.8 | 0.2% | Dec 29, 2025 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_act... |
| CVE-2024-25181 | CRITICAL | 9.1 | 0.3% | Dec 29, 2025 | A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSR... |
| CVE-2024-44065 | CRITICAL | 9.8 | 0.4% | Dec 26, 2025 | Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in th... |
| CVE-2024-42718 | MEDIUM | 6.5 | 0.6% | Dec 26, 2025 | A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially craft... |
| CVE-2024-29720 | MEDIUM | 5.5 | 0.2% | Dec 26, 2025 | An issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 allows a local attacker to obtain sensitive information via... |
| CVE-2024-40317 | MEDIUM | 6.1 | 0.2% | Dec 24, 2025 | A reflected cross-site scripting (XSS) vulnerability in MyNET up to v26.08 allows attackers to execute arbitrary code in... |
| CVE-2024-39037 | MEDIUM | 6.5 | 0.2% | Dec 24, 2025 | MyNET up to v26.08.316 was discovered to contain an Unauthenticated SQL Injection vulnerability via the intmenu paramete... |
| CVE-2024-35322 | MEDIUM | 6.1 | 0.2% | Dec 24, 2025 | MyNET up to v26.08 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the ficheiro param... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now