2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7952 | HIGH | 8.7 | — | Sep 1, 2026 | A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to ... |
| CVE-2024-14047 | HIGH | 7.1 | 0.1% | Sep 1, 2026 | A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by u... |
| CVE-2024-10085 | HIGH | 8.2 | — | Sep 1, 2026 | CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of... |
| CVE-2024-58379 | MEDIUM | 5.3 | 0.3% | Aug 31, 2026 | nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUr... |
| CVE-2024-58378 | — | — | 0.3% | Aug 25, 2026 | Rejected reason: This CVE ID has been rejected as a duplicate. |
| CVE-2024-58377 | — | — | 0.1% | Aug 25, 2026 | Rejected reason: This CVE ID has been rejected as a duplicate. |
| CVE-2024-13942 | HIGH | 7.6 | 0.2% | Aug 19, 2026 | Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack in case of booting from external me... |
| CVE-2024-58376 | MEDIUM | 6.7 | 0.7% | Aug 19, 2026 | Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAli... |
| CVE-2024-14046 | MEDIUM | 6.3 | 0.4% | Aug 18, 2026 | A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController ... |
| CVE-2024-14045 | MEDIUM | 6.3 | 0.4% | Aug 18, 2026 | A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/... |
| CVE-2024-58375 | HIGH | 7.5 | 0.4% | Aug 16, 2026 | OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into... |
| CVE-2024-13784 | CRITICAL | 9.8 | 0.8% | Aug 16, 2026 | The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection... |
| CVE-2024-58374 | HIGH | 7.5 | 0.7% | Aug 13, 2026 | Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows r... |
| CVE-2024-27253 | CRITICAL | 10 | 0.3% | Aug 12, 2026 | IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform... |
| CVE-2024-14044 | MEDIUM | 6.3 | 0.5% | Aug 12, 2026 | A vulnerability was identified in Open5GS up to 2.7.1. This issue affects the function pcrf_rx_aar_cb of the file src/pc... |
| CVE-2024-14043 | MEDIUM | 6.3 | 0.5% | Aug 12, 2026 | A vulnerability was determined in Open5GS up to 2.7.1. This vulnerability affects the function mme_s6a_subscription_data... |
| CVE-2024-14042 | MEDIUM | 6.3 | 0.5% | Aug 11, 2026 | A vulnerability was found in Open5GS up to 2.7.1. This affects the function hss_ogs_diam_s6a_air_cb/hss_ogs_diam_s6a_ulr... |
| CVE-2024-6541 | MEDIUM | 6.8 | 0.3% | Aug 6, 2026 | The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dy... |
| CVE-2024-39024 | HIGH | 8.8 | 0.7% | Aug 6, 2026 | In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution. |
| CVE-2024-8995 | MEDIUM | 4.9 | 0.1% | Aug 6, 2026 | Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This a... |
| CVE-2024-6832 | HIGH | 7.5 | 0.3% | Aug 6, 2026 | The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not mainta... |
| CVE-2024-10302 | MEDIUM | 5.8 | 0.2% | Aug 6, 2026 | The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allo... |
| CVE-2024-40683 | MEDIUM | 6.3 | 0.3% | Jul 30, 2026 | IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2,... |
| CVE-2024-25039 | HIGH | 7.5 | 0.5% | Jul 30, 2026 | IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1... |
| CVE-2024-14041 | MEDIUM | 5.9 | 0.3% | Jul 28, 2026 | In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polyno... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now