2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-58301 | CRITICAL | 9.3 | 0.3% | Dec 11, 2025 | Purei CMS 1.0 contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queri... |
| CVE-2024-58300 | HIGH | 8.7 | 0.3% | Dec 11, 2025 | Siklu MultiHaul TG series devices before version 2.0.0 contain an unauthenticated vulnerability that allows remote attac... |
| CVE-2024-58298 | CRITICAL | 9.2 | 0.7% | Dec 11, 2025 | Compuware iStrobe Web 20.13 contains a pre-authentication remote code execution vulnerability that allows unauthenticate... |
| CVE-2024-58297 | MEDIUM | 5.4 | 0.2% | Dec 11, 2025 | PyroCMS v3.0.1 contains a stored cross-site scripting vulnerability in the admin redirects configuration that allows att... |
| CVE-2024-58296 | MEDIUM | 5.3 | 0.3% | Dec 11, 2025 | CE Phoenix v3.0.1 contains a stored cross-site scripting vulnerability in the currencies administration panel that allow... |
| CVE-2024-58295 | HIGH | 8.6 | 0.5% | Dec 11, 2025 | ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload ma... |
| CVE-2024-58294 | HIGH | 8.8 | 3.1% | Dec 11, 2025 | FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with va... |
| CVE-2024-58293 | HIGH | 8.6 | 0.3% | Dec 11, 2025 | Akaunting 3.1.8 contains a server-side template injection vulnerability that allows authenticated administrators to exec... |
| CVE-2024-58292 | MEDIUM | 5.3 | 0.4% | Dec 11, 2025 | XMB Forum 1.9.12.06 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to... |
| CVE-2024-58291 | MEDIUM | 5.3 | 0.3% | Dec 11, 2025 | Flatboard 3.2 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject ma... |
| CVE-2024-58290 | CRITICAL | 9.3 | 0.3% | Dec 11, 2025 | Xhibiter NFT Marketplace 1.10.2 contains a SQL injection vulnerability in the collections endpoint that allows attackers... |
| CVE-2024-58289 | MEDIUM | 5.4 | 0.2% | Dec 11, 2025 | Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject mal... |
| CVE-2024-58288 | HIGH | 8.7 | 0.3% | Dec 11, 2025 | Genexus Protection Server 9.7.2.10 contains an unquoted service path vulnerability in the protsrvservice Windows service... |
| CVE-2024-58287 | HIGH | 8.8 | 3.0% | Dec 11, 2025 | reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that all... |
| CVE-2024-58286 | CRITICAL | 9.3 | 0.5% | Dec 11, 2025 | dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through... |
| CVE-2024-42197 | MEDIUM | 5.5 | 0.1% | Dec 11, 2025 | HCL Workload Scheduler stores user credentials in plain text which can be read by a local user. |
| CVE-2024-8273 | HIGH | 8.8 | 0.3% | Dec 11, 2025 | Authentication Bypass by Spoofing vulnerability in HYPR Server allows Identity Spoofing.This issue affects Server: befor... |
| CVE-2024-40593 | MEDIUM | 4.4 | 0.1% | Dec 11, 2025 | A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, ... |
| CVE-2024-58285 | MEDIUM | 5.4 | 0.2% | Dec 10, 2025 | Chyrp 2.5.2 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scr... |
| CVE-2024-58284 | HIGH | 7.2 | 0.9% | Dec 10, 2025 | PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inj... |
| CVE-2024-58283 | HIGH | 8.8 | 0.6% | Dec 10, 2025 | WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload mali... |
| CVE-2024-58282 | HIGH | 7.2 | 0.9% | Dec 10, 2025 | Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload mali... |
| CVE-2024-58281 | HIGH | 8.8 | 0.8% | Dec 10, 2025 | Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP... |
| CVE-2024-58280 | HIGH | 8.8 | 0.8% | Dec 10, 2025 | CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file exten... |
| CVE-2024-58279 | HIGH | 8.8 | 0.8% | Dec 10, 2025 | appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to uplo... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now