2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32387 | MEDIUM | 5.7 | 0.2% | Jul 16, 2026 | An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitiv... |
| CVE-2024-32385 | MEDIUM | 4.3 | 0.2% | Jul 16, 2026 | An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitiv... |
| CVE-2024-58360 | MEDIUM | 6.9 | 0.3% | Jul 16, 2026 | stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verifica... |
| CVE-2024-56141 | MEDIUM | 5 | 0.1% | Jul 7, 2026 | Minosoft is an open-source, multi-version Minecraft Java Edition client written in Kotlin. Starting in commit f1ae30e2b0... |
| CVE-2024-1248 | MEDIUM | 5.3 | 0.2% | Jul 4, 2026 | The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segrega... |
| CVE-2024-51454 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 th... |
| CVE-2024-54178 | MEDIUM | 6.5 | 0.2% | Jun 22, 2026 | IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authen... |
| CVE-2024-27928 | MEDIUM | 5.9 | 0.3% | Jun 17, 2026 | vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, if an attacker hacks ... |
| CVE-2024-47477 | MEDIUM | 6.5 | 0.1% | Jun 17, 2026 | Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote un... |
| CVE-2024-37496 | MEDIUM | 4.3 | 0.2% | Jun 17, 2026 | Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Contro... |
| CVE-2024-37210 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security ... |
| CVE-2024-35690 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded... |
| CVE-2024-35648 | MEDIUM | 4.3 | 0.1% | Jun 17, 2026 | Cross-Site request forgery (CSRF) vulnerability in Andy Moyle Emergency Password Reset allows Cross Site Request Forgery... |
| CVE-2024-34810 | MEDIUM | 4.3 | 0.1% | Jun 17, 2026 | Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery. This iss... |
| CVE-2024-33909 | MEDIUM | 5.3 | 0.2% | Jun 17, 2026 | Missing Authorization vulnerability in Avirtum iPages Flipbook allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2024-33685 | MEDIUM | 4.3 | 0.2% | Jun 17, 2026 | Missing Authorization vulnerability in Jegstudio Startupzy startupzy allows Exploiting Incorrectly Configured Access Con... |
| CVE-2024-31435 | MEDIUM | 4.3 | 0.2% | Jun 17, 2026 | : Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Acce... |
| CVE-2024-24709 | MEDIUM | 4.3 | 0.2% | Jun 17, 2026 | Missing Authorization vulnerability in Shareaholic allows Exploiting Incorrectly Configured Access Control Security Leve... |
| CVE-2024-30476 | MEDIUM | 5.4 | 0.2% | Jun 16, 2026 | PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerStore Manager. A remote authenticated low-pr... |
| CVE-2024-22451 | MEDIUM | 6.7 | 0.1% | Jun 16, 2026 | Dell Peripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncontrolled search path element vulnerability. An att... |
| CVE-2024-45636 | MEDIUM | 4.4 | 0.1% | Jun 11, 2026 | IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileg... |
| CVE-2024-32110 | MEDIUM | 4.3 | 0.1% | Jun 11, 2026 | Cross-Site request forgery (CSRF) vulnerability in Magepeople inc. WpEvently allows Cross Site Request Forgery. This is... |
| CVE-2024-21944 | MEDIUM | 5.3 | 0.2% | Jun 10, 2026 | Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, r... |
| CVE-2024-58350 | MEDIUM | 4 | 0.1% | Jun 10, 2026 | Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initializati... |
| CVE-2024-27891 | MEDIUM | 6.9 | 0.3% | Jun 4, 2026 | On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now