2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39730 | MEDIUM | 5.4 | 0.2% | Jun 28, 2025 | IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim.... |
| CVE-2024-36347 | MEDIUM | 6.4 | 0.1% | Jun 27, 2025 | Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator pri... |
| CVE-2024-56915 | MEDIUM | 6.5 | 0.4% | Jun 26, 2025 | Netbox Community v4.1.7 and fixed in v.4.2.2 is vulnerable to Cross Site Scripting (XSS) via the RSS feed widget. |
| CVE-2024-11584 | MEDIUM | 5.3 | 0.1% | Jun 26, 2025 | cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grant... |
| CVE-2024-57708 | MEDIUM | 5.7 | 0.9% | Jun 25, 2025 | An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __... |
| CVE-2024-51984 | MEDIUM | 6.8 | 0.8% | Jun 25, 2025 | An authenticated attacker can reconfigure the target device to use an external service (such as LDAP or FTP) controlled ... |
| CVE-2024-51981 | MEDIUM | 5.3 | 0.8% | Jun 25, 2025 | An unauthenticated attacker may perform a blind server side request forgery (SSRF), due to a CLRF injection issue that c... |
| CVE-2024-51980 | MEDIUM | 5.3 | 0.9% | Jun 25, 2025 | An unauthenticated attacker may perform a limited server side request forgery (SSRF), forcing the target device to open ... |
| CVE-2024-51977 | MEDIUM | 5.3 | 76.6% | Jun 25, 2025 | An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or t... |
| CVE-2024-56916 | MEDIUM | 6.1 | 0.3% | Jun 24, 2025 | In Netbox Community 4.1.7, once authenticated, Configuration History > Add`is vulnerable to cross-site scripting (XSS) d... |
| CVE-2024-56918 | MEDIUM | 6.1 | 0.3% | Jun 24, 2025 | In Netbox Community 4.1.7, the login page is vulnerable to cross-site scripting (XSS), which allows a privileged, authen... |
| CVE-2024-3511 | MEDIUM | 4.3 | 0.2% | Jun 23, 2025 | An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned f... |
| CVE-2024-54172 | MEDIUM | 4.3 | 0.1% | Jun 18, 2025 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnera... |
| CVE-2024-54183 | MEDIUM | 5.4 | 0.2% | Jun 18, 2025 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnera... |
| CVE-2024-40570 | MEDIUM | 6.5 | 0.4% | Jun 17, 2025 | SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_data... |
| CVE-2024-25573 | MEDIUM | 6.9 | 0.3% | Jun 15, 2025 | Unsanitized user-supplied data saved in the PingFederate Administrative Console could trigger the execution of JavaScrip... |
| CVE-2024-38825 | MEDIUM | 6.4 | 0.1% | Jun 13, 2025 | The salt.auth.pki module does not properly authenticate callers. The "password" field contains a public certificate whic... |
| CVE-2024-55567 | MEDIUM | 6.7 | 0.1% | Jun 12, 2025 | Improper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55.... |
| CVE-2024-44906 | MEDIUM | 6.5 | 0.3% | Jun 12, 2025 | uptrace pgdriver v1.2.1 was discovered to contain a SQL injection vulnerability via the appendArg function in /pgdriver/... |
| CVE-2024-44905 | MEDIUM | 6.5 | 0.4% | Jun 12, 2025 | go-pg pg v10.13.0 was discovered to contain a SQL injection vulnerability via the component /types/append_value.go. |
| CVE-2024-9512 | MEDIUM | 5.9 | 0.2% | Jun 12, 2025 | An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prio... |
| CVE-2024-35295 | MEDIUM | 6.1 | 0.2% | Jun 11, 2025 | A vulnerability has been identified in Perfect Harmony GH180 (All versions >= V8.0 < V8.3.3 with NXGPro+ controller manu... |
| CVE-2024-8270 | MEDIUM | 5.5 | 0.2% | Jun 11, 2025 | The macOS Rocket.Chat application is affected by a vulnerability that allows bypassing Transparency, Consent, and Contr... |
| CVE-2024-41505 | MEDIUM | 6.1 | 0.2% | Jun 10, 2025 | Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the "Pessoas" (persons) section... |
| CVE-2024-41504 | MEDIUM | 6.1 | 0.2% | Jun 10, 2025 | Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS). In the "Oportunidades" (opportuni... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now