2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9183 | MEDIUM | 6.4 | 0.2% | Dec 5, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, a... |
| CVE-2024-58278 | HIGH | 8.5 | 0.2% | Dec 4, 2025 | perl2exe <= V30.10C contains an arbitrary code execution vulnerability that allows local authenticated attackers to exec... |
| CVE-2024-58277 | HIGH | 8.7 | 0.4% | Dec 4, 2025 | R Radio Network FM Transmitter 1.07 allows unauthenticated attackers to access the admin user's password through the sys... |
| CVE-2024-58276 | HIGH | 8.7 | 0.4% | Dec 4, 2025 | Obi08/Enrollment System 1.0 contains a SQL injection vulnerability in the keyword parameter of /get_subject.php that all... |
| CVE-2024-58275 | HIGH | 8.7 | 1.8% | Dec 4, 2025 | Easywall 0.3.1 allows authenticated remote command execution via a command injection vulnerability in the /ports-save en... |
| CVE-2024-5401 | HIGH | 8.8 | 0.4% | Dec 4, 2025 | Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager... |
| CVE-2024-45539 | HIGH | 7.5 | 0.5% | Dec 4, 2025 | Out-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2... |
| CVE-2024-45538 | CRITICAL | 9.6 | 0.4% | Dec 4, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-6... |
| CVE-2024-3884 | HIGH | 7.5 | 1.4% | Dec 3, 2025 | A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDe... |
| CVE-2024-32643 | HIGH | 7.5 | 0.4% | Dec 3, 2025 | Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, if the URL to the ... |
| CVE-2024-32642 | HIGH | 8.8 | 0.2% | Dec 3, 2025 | Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerabl... |
| CVE-2024-32641 | CRITICAL | 9.8 | 12.3% | Dec 3, 2025 | Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 a... |
| CVE-2024-45675 | HIGH | 7.8 | 0.1% | Dec 2, 2025 | IBM Informix Dynamic Server 14.10 could allow a local user on the system to log into the Informix server as administrato... |
| CVE-2024-51999 | — | — | — | Dec 1, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error and is not a ... |
| CVE-2024-53684 | HIGH | 8.8 | 0.2% | Dec 1, 2025 | A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1... |
| CVE-2024-49572 | MEDIUM | 6.5 | 0.3% | Dec 1, 2025 | A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A special... |
| CVE-2024-48894 | HIGH | 7.5 | 1.1% | Dec 1, 2025 | A cleartext transmission vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A spe... |
| CVE-2024-48882 | HIGH | 7.5 | 0.5% | Dec 1, 2025 | A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A special... |
| CVE-2024-45370 | HIGH | 7.3 | 0.2% | Dec 1, 2025 | An authentication bypass vulnerability exists in the User profile management functionality of Socomec Easy Config System... |
| CVE-2024-39148 | HIGH | 8.1 | 0.5% | Dec 1, 2025 | The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated ... |
| CVE-2024-32388 | MEDIUM | 5.3 | 1.4% | Dec 1, 2025 | Due to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP... |
| CVE-2024-32384 | HIGH | 7.4 | 0.1% | Dec 1, 2025 | Kerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS sup... |
| CVE-2024-56089 | HIGH | 7.5 | 0.3% | Dec 1, 2025 | An issue in Technitium through v13.2.2 enables attackers to conduct a DNS cache poisoning attack and inject fake respons... |
| CVE-2024-5540 | MEDIUM | 6.9 | 0.3% | Nov 27, 2025 | The reflective cross-site scripting vulnerability found in ALC WebCTRL and Carrier i-Vu in versions older than 8.0 affec... |
| CVE-2024-5539 | CRITICAL | 9.2 | 0.3% | Nov 27, 2025 | The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now