2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-58272 | — | — | — | Oct 30, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2... |
| CVE-2024-14009 | HIGH | 7.2 | 1.1% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.0.1 contain a privilege escalation vulnerability in the System Profile component. The... |
| CVE-2024-14008 | HIGH | 7.2 | 2.2% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.3.2 contain a remote command execution vulnerability in the WinRM Configuration Wizar... |
| CVE-2024-14006 | MEDIUM | 6.1 | 0.4% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-su... |
| CVE-2024-14005 | HIGH | 8.8 | 4.2% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard. Insufficient valida... |
| CVE-2024-14004 | HIGH | 8.8 | 1.0% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to NagVis configuration handli... |
| CVE-2024-14003 | CRITICAL | 9.8 | 2.1% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data ... |
| CVE-2024-14002 | MEDIUM | 5.5 | 1.2% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.4 contain a local file inclusion (LFI) vulnerability via its NagVis integration. An... |
| CVE-2024-14001 | MEDIUM | 5.4 | 0.5% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Executive Summary Report com... |
| CVE-2024-14000 | MEDIUM | 5.4 | 0.5% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Capacity Planning Report com... |
| CVE-2024-13999 | CRITICAL | 9.8 | 1.8% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP... |
| CVE-2024-13996 | CRITICAL | 9.8 | 1.0% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password... |
| CVE-2024-13995 | HIGH | 8.8 | 1.2% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive user account inform... |
| CVE-2024-13994 | CRITICAL | 9.8 | 0.8% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option i... |
| CVE-2024-13993 | MEDIUM | 6.1 | 0.7% | Oct 30, 2025 | Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) via the login page whe... |
| CVE-2024-14012 | HIGH | 7.3 | 0.1% | Oct 29, 2025 | Potential privilege escalation issue in Revenera InstallShield version 2023 R1 running a renamed Setup.exe on Windows. W... |
| CVE-2024-58269 | MEDIUM | 4.3 | 0.3% | Oct 29, 2025 | A vulnerability has been identified in Rancher Manager, where sensitive information, including secret data, cluster imp... |
| CVE-2024-45162 | CRITICAL | 9.8 | 0.5% | Oct 29, 2025 | A stack-based buffer overflow issue was discovered in the phddns client in Blu-Castle BCUM221E 1.0.0P220507 via the pass... |
| CVE-2024-45161 | MEDIUM | 4.6 | 0.1% | Oct 29, 2025 | A CSRF issue was discovered in the administrative web GUI in Blu-Castle BCUM221E 1.0.0P220507. This can be exploited via... |
| CVE-2024-14011 | — | — | — | Oct 23, 2025 | Rejected reason: This is a duplicate. |
| CVE-2024-58274 | HIGH | 8.3 | 17.5% | Oct 22, 2025 | Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a comm... |
| CVE-2024-55568 | HIGH | 7.5 | 0.5% | Oct 20, 2025 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128... |
| CVE-2024-31573 | MEDIUM | 4 | 0.2% | Oct 17, 2025 | XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (us... |
| CVE-2024-42192 | MEDIUM | 5.5 | 0.1% | Oct 16, 2025 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access... |
| CVE-2024-56143 | HIGH | 8.2 | 0.4% | Oct 16, 2025 | Strapi is an open-source headless content management system. In versions from 5.0.0 to before 5.5.2, the lookup operator... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now