2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-58311 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access... |
| CVE-2024-58305 | HIGH | 8.8 | 0.4% | Dec 12, 2025 | WonderCMS 4.3.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious JavaScript throu... |
| CVE-2024-58299 | CRITICAL | 9.8 | 0.7% | Dec 12, 2025 | PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execu... |
| CVE-2024-14010 | CRITICAL | 9.8 | 1.2% | Dec 12, 2025 | Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute a... |
| CVE-2024-58313 | HIGH | 7.2 | 0.5% | Dec 11, 2025 | xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative pr... |
| CVE-2024-58312 | HIGH | 7.5 | 1.0% | Dec 11, 2025 | xbtitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system ... |
| CVE-2024-58310 | HIGH | 8.7 | 0.8% | Dec 11, 2025 | APC Network Management Card 4 contains a path traversal vulnerability that allows unauthenticated attackers to access se... |
| CVE-2024-58309 | CRITICAL | 9.8 | 0.5% | Dec 11, 2025 | xbtitFM 4.1.18 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate databa... |
| CVE-2024-58308 | CRITICAL | 9.8 | 0.6% | Dec 11, 2025 | Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authenticatio... |
| CVE-2024-58307 | HIGH | 8.8 | 0.4% | Dec 11, 2025 | CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authent... |
| CVE-2024-58306 | HIGH | 8.7 | 0.4% | Dec 11, 2025 | minaliC 2.0.0 contains a denial of service vulnerability that allows remote attackers to crash the web server by sending... |
| CVE-2024-58304 | MEDIUM | 6.1 | — | Dec 11, 2025 | SPA-CART CMS before 2.0.0 contains a stored cross-site scripting vulnerability in the product description parameter that... |
| CVE-2024-58303 | HIGH | 8.6 | 0.5% | Dec 11, 2025 | FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject... |
| CVE-2024-58302 | MEDIUM | 6.9 | 0.3% | Dec 11, 2025 | FoF Pretty Mail 1.1.2 contains a local file inclusion vulnerability that allows administrative users to include arbitrar... |
| CVE-2024-58301 | CRITICAL | 9.3 | 0.3% | Dec 11, 2025 | Purei CMS 1.0 contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queri... |
| CVE-2024-58300 | HIGH | 8.7 | 0.4% | Dec 11, 2025 | Siklu MultiHaul TG series devices before version 2.0.0 contain an unauthenticated vulnerability that allows remote attac... |
| CVE-2024-58298 | CRITICAL | 9.2 | 1.0% | Dec 11, 2025 | Compuware iStrobe Web 20.13 contains a pre-authentication remote code execution vulnerability that allows unauthenticate... |
| CVE-2024-58297 | MEDIUM | 5.4 | 0.2% | Dec 11, 2025 | PyroCMS v3.0.1 contains a stored cross-site scripting vulnerability in the admin redirects configuration that allows att... |
| CVE-2024-58296 | MEDIUM | 5.3 | 0.4% | Dec 11, 2025 | CE Phoenix v3.0.1 contains a stored cross-site scripting vulnerability in the currencies administration panel that allow... |
| CVE-2024-58295 | HIGH | 8.6 | 0.6% | Dec 11, 2025 | ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload ma... |
| CVE-2024-58294 | HIGH | 8.8 | 3.1% | Dec 11, 2025 | FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with va... |
| CVE-2024-58293 | HIGH | 8.6 | 0.3% | Dec 11, 2025 | Akaunting 3.1.8 contains a server-side template injection vulnerability that allows authenticated administrators to exec... |
| CVE-2024-58292 | MEDIUM | 5.3 | 0.4% | Dec 11, 2025 | XMB Forum 1.9.12.06 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to... |
| CVE-2024-58291 | MEDIUM | 5.3 | 0.3% | Dec 11, 2025 | Flatboard 3.2 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject ma... |
| CVE-2024-58290 | CRITICAL | 9.3 | 0.4% | Dec 11, 2025 | Xhibiter NFT Marketplace 1.10.2 contains a SQL injection vulnerability in the collections endpoint that allows attackers... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now