2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-58335 | MEDIUM | 5 | 0.2% | Dec 24, 2025 | OpenXRechnungToolbox through 2024-10-05-3.0.0 before 6c50e89 allows XXE because the disallow-doctype-decl feature is not... |
| CVE-2024-57521 | CRITICAL | 10 | 0.6% | Dec 23, 2025 | SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the creat... |
| CVE-2024-10398 | — | — | — | Dec 23, 2025 | Rejected reason: This CVE id was assigned but later discarded. |
| CVE-2024-9684 | HIGH | 7.5 | 0.3% | Dec 23, 2025 | FreyrSCADA/IEC-60870-5-104 server v21.06.008 allows remote attackers to cause a denial of service by sending specific me... |
| CVE-2024-24844 | HIGH | 7.5 | 0.2% | Dec 23, 2025 | Missing Authorization vulnerability in IdeaBox Creations PowerPack Pro for Elementor allows Exploiting Incorrectly Confi... |
| CVE-2024-27708 | CRITICAL | 9.6 | 0.6% | Dec 22, 2025 | Iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and before allows a remote attacker t... |
| CVE-2024-25812 | MEDIUM | 6.1 | 0.2% | Dec 22, 2025 | MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the src parameter. |
| CVE-2024-35321 | MEDIUM | 4.3 | 0.3% | Dec 22, 2025 | MyNET up to v26.08 was discovered to contain a Reflected cross-site scripting (XSS) vulnerability via the msgtipo parame... |
| CVE-2024-25814 | MEDIUM | 6.1 | 0.2% | Dec 22, 2025 | MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the msg parameter. |
| CVE-2024-49587 | CRITICAL | 9.1 | 0.3% | Dec 19, 2025 | Glutton V1 service endpoints were exposed without any authentication on Gotham stacks, this could have allowed users tha... |
| CVE-2024-58323 | MEDIUM | 5.4 | 0.1% | Dec 18, 2025 | A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Ch... |
| CVE-2024-58322 | MEDIUM | 5.4 | 0.1% | Dec 18, 2025 | A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious code into shipping... |
| CVE-2024-58321 | MEDIUM | 5.4 | 0.1% | Dec 18, 2025 | A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form v... |
| CVE-2024-58320 | MEDIUM | 6.9 | 0.2% | Dec 18, 2025 | An information disclosure vulnerability in Kentico Xperience allows public users to access sensitive administration inte... |
| CVE-2024-58319 | MEDIUM | 6.1 | 0.2% | Dec 18, 2025 | A reflected cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the... |
| CVE-2024-58318 | MEDIUM | 6.1 | 0.1% | Dec 18, 2025 | A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the ri... |
| CVE-2024-58317 | MEDIUM | 6.9 | 0.2% | Dec 18, 2025 | A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL requirements when sett... |
| CVE-2024-46062 | HIGH | 7.8 | 0.2% | Dec 17, 2025 | Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside t... |
| CVE-2024-46060 | HIGH | 7.8 | 0.2% | Dec 17, 2025 | Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside th... |
| CVE-2024-29371 | HIGH | 7.5 | 0.2% | Dec 17, 2025 | In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encry... |
| CVE-2024-29370 | MEDIUM | 5.3 | 0.2% | Dec 17, 2025 | In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) c... |
| CVE-2024-44599 | HIGH | 8.3 | 0.4% | Dec 15, 2025 | FNT Command 13.4.0 is vulnerable to Directory Traversal. |
| CVE-2024-44598 | HIGH | 8.8 | 0.4% | Dec 15, 2025 | FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module. |
| CVE-2024-58316 | HIGH | 8.7 | 0.5% | Dec 12, 2025 | Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows... |
| CVE-2024-58314 | HIGH | 8.8 | 1.4% | Dec 12, 2025 | Atcom 100M IP Phones firmware version 2.7.x.x contains an authenticated command injection vulnerability in the web confi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now