2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-40489 | CRITICAL | 9.8 | 0.5% | Apr 1, 2026 | There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows a... |
| CVE-2024-44722 | CRITICAL | 9.8 | 0.5% | Mar 20, 2026 | SysAK v2.0 and before is vulnerable to command execution via aaa;cat /etc/passwd. |
| CVE-2024-57854 | CRITICAL | 9.1 | 0.4% | Mar 5, 2026 | Net::NSCA::Client versions through 0.009002 for Perl uses a poor random number generator. Version v0.003 switched to us... |
| CVE-2024-55026 | CRITICAL | 9.8 | 0.3% | Mar 3, 2026 | An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers... |
| CVE-2024-55024 | CRITICAL | 9.8 | 0.4% | Mar 3, 2026 | An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v202310... |
| CVE-2024-55020 | CRITICAL | 9.8 | 1.7% | Mar 3, 2026 | A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS ... |
| CVE-2024-58041 | CRITICAL | 9.1 | 0.4% | Feb 24, 2026 | Smolder versions through 1.51 for Perl uses insecure rand() function for cryptographic functions. Smolder 1.51 and earl... |
| CVE-2024-5986 | CRITICAL | 9.1 | 0.6% | Feb 2, 2026 | A vulnerability in h2oai/h2o-3 version 3.46.0.1 allows remote attackers to write arbitrary data to any file on the serve... |
| CVE-2024-2356 | CRITICAL | 9.6 | 0.8% | Feb 2, 2026 | A Local File Inclusion (LFI) vulnerability exists in the '/reinstall_extension' endpoint of the parisneo/lollms-webui ap... |
| CVE-2024-58338 | CRITICAL | 10 | 0.7% | Dec 30, 2025 | Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed ... |
| CVE-2024-27480 | CRITICAL | 9.8 | 0.3% | Dec 29, 2025 | givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload. |
| CVE-2024-25182 | CRITICAL | 9.8 | 0.3% | Dec 29, 2025 | givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php. |
| CVE-2024-25181 | CRITICAL | 9.1 | 0.3% | Dec 29, 2025 | A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSR... |
| CVE-2024-44065 | CRITICAL | 9.8 | 0.4% | Dec 26, 2025 | Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in th... |
| CVE-2024-57521 | CRITICAL | 10 | 0.6% | Dec 23, 2025 | SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the creat... |
| CVE-2024-27708 | CRITICAL | 9.6 | 0.5% | Dec 22, 2025 | Iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and before allows a remote attacker t... |
| CVE-2024-49587 | CRITICAL | 9.1 | 0.3% | Dec 19, 2025 | Glutton V1 service endpoints were exposed without any authentication on Gotham stacks, this could have allowed users tha... |
| CVE-2024-58311 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access... |
| CVE-2024-58299 | CRITICAL | 9.8 | 0.7% | Dec 12, 2025 | PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execu... |
| CVE-2024-14010 | CRITICAL | 9.8 | 1.0% | Dec 12, 2025 | Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute a... |
| CVE-2024-58309 | CRITICAL | 9.8 | 0.5% | Dec 11, 2025 | xbtitFM 4.1.18 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate databa... |
| CVE-2024-58308 | CRITICAL | 9.8 | 0.6% | Dec 11, 2025 | Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authenticatio... |
| CVE-2024-58301 | CRITICAL | 9.3 | 0.3% | Dec 11, 2025 | Purei CMS 1.0 contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queri... |
| CVE-2024-58298 | CRITICAL | 9.2 | 0.7% | Dec 11, 2025 | Compuware iStrobe Web 20.13 contains a pre-authentication remote code execution vulnerability that allows unauthenticate... |
| CVE-2024-58290 | CRITICAL | 9.3 | 0.3% | Dec 11, 2025 | Xhibiter NFT Marketplace 1.10.2 contains a SQL injection vulnerability in the collections endpoint that allows attackers... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now