2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-58319 | MEDIUM | 6.1 | 0.2% | Dec 18, 2025 | A reflected cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the... |
| CVE-2024-58318 | MEDIUM | 6.1 | 0.1% | Dec 18, 2025 | A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the ri... |
| CVE-2024-58317 | MEDIUM | 6.9 | 0.2% | Dec 18, 2025 | A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL requirements when sett... |
| CVE-2024-46062 | HIGH | 7.8 | 0.2% | Dec 17, 2025 | Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside t... |
| CVE-2024-46060 | HIGH | 7.8 | 0.2% | Dec 17, 2025 | Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside th... |
| CVE-2024-29371 | HIGH | 7.5 | 0.2% | Dec 17, 2025 | In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encry... |
| CVE-2024-29370 | MEDIUM | 5.3 | 0.2% | Dec 17, 2025 | In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) c... |
| CVE-2024-44599 | HIGH | 8.3 | 0.4% | Dec 15, 2025 | FNT Command 13.4.0 is vulnerable to Directory Traversal. |
| CVE-2024-44598 | HIGH | 8.8 | 0.4% | Dec 15, 2025 | FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module. |
| CVE-2024-58316 | HIGH | 8.7 | 0.5% | Dec 12, 2025 | Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows... |
| CVE-2024-58314 | HIGH | 8.8 | 1.4% | Dec 12, 2025 | Atcom 100M IP Phones firmware version 2.7.x.x contains an authenticated command injection vulnerability in the web confi... |
| CVE-2024-58311 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access... |
| CVE-2024-58305 | HIGH | 8.8 | 0.4% | Dec 12, 2025 | WonderCMS 4.3.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious JavaScript throu... |
| CVE-2024-58299 | CRITICAL | 9.8 | 0.7% | Dec 12, 2025 | PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execu... |
| CVE-2024-14010 | CRITICAL | 9.8 | 1.0% | Dec 12, 2025 | Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute a... |
| CVE-2024-58313 | HIGH | 7.2 | 0.5% | Dec 11, 2025 | xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative pr... |
| CVE-2024-58312 | HIGH | 7.5 | 1.0% | Dec 11, 2025 | xbtitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system ... |
| CVE-2024-58310 | HIGH | 8.7 | 0.8% | Dec 11, 2025 | APC Network Management Card 4 contains a path traversal vulnerability that allows unauthenticated attackers to access se... |
| CVE-2024-58309 | CRITICAL | 9.8 | 0.5% | Dec 11, 2025 | xbtitFM 4.1.18 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate databa... |
| CVE-2024-58308 | CRITICAL | 9.8 | 0.6% | Dec 11, 2025 | Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authenticatio... |
| CVE-2024-58307 | HIGH | 8.8 | 0.4% | Dec 11, 2025 | CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authent... |
| CVE-2024-58306 | HIGH | 8.7 | 0.4% | Dec 11, 2025 | minaliC 2.0.0 contains a denial of service vulnerability that allows remote attackers to crash the web server by sending... |
| CVE-2024-58304 | HIGH | 7.5 | 0.4% | Dec 11, 2025 | SPA-CART CMS 1.9.0.3 contains a stored cross-site scripting vulnerability in the product description parameter that allo... |
| CVE-2024-58303 | HIGH | 8.6 | 0.5% | Dec 11, 2025 | FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject... |
| CVE-2024-58302 | MEDIUM | 6.9 | 0.3% | Dec 11, 2025 | FoF Pretty Mail 1.1.2 contains a local file inclusion vulnerability that allows administrative users to include arbitrar... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now