2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13991 | HIGH | 8.7 | 0.4% | Oct 15, 2025 | Huijietong Cloud Video Platform contains a path traversal vulnerability that allows an unauthenticated attacker can supp... |
| CVE-2024-50571 | HIGH | 7.2 | 0.5% | Oct 14, 2025 | A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.... |
| CVE-2024-48891 | HIGH | 7 | 0.5% | Oct 14, 2025 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in ... |
| CVE-2024-47569 | MEDIUM | 4.3 | 0.4% | Oct 14, 2025 | A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7... |
| CVE-2024-33507 | CRITICAL | 9.1 | 0.4% | Oct 14, 2025 | An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in For... |
| CVE-2024-26008 | MEDIUM | 5.3 | 0.4% | Oct 14, 2025 | An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 a... |
| CVE-2024-44088 | MEDIUM | 6.1 | 0.6% | Oct 14, 2025 | Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability all... |
| CVE-2024-6211 | — | — | — | Oct 13, 2025 | Rejected reason: loading template... |
| CVE-2024-56804 | HIGH | 8.8 | 0.3% | Oct 3, 2025 | An SQL injection vulnerability has been reported to affect Video Station. If a remote attacker gains a user account, the... |
| CVE-2024-58267 | HIGH | 8 | 0.2% | Oct 2, 2025 | A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI tool is... |
| CVE-2024-58260 | HIGH | 7.6 | 0.5% | Oct 2, 2025 | A vulnerability has been identified within Rancher Manager where a missing server-side validation on the `.username` fie... |
| CVE-2024-57494 | MEDIUM | 6.5 | 0.3% | Oct 1, 2025 | Cross Site Scripting vulnerability in Neto E-Commerce CMS v.6.313.0 through v.6.3115 allows a remote attacker to escalat... |
| CVE-2024-55017 | HIGH | 7.5 | 0.3% | Sep 30, 2025 | Account Takeover in Corezoid 6.6.0 in the OAuth2 implementation via an open redirect in the redirect_uri parameter allow... |
| CVE-2024-58040 | CRITICAL | 9.1 | 0.2% | Sep 30, 2025 | Crypt::RandomEncryption for Perl version 0.01 uses insecure rand() function during encryption. |
| CVE-2024-57412 | HIGH | 7.5 | 0.3% | Sep 29, 2025 | An issue in SunOS Omnios v5.11 allows attackers to cause a Denial of Service (DoS) via repeatedly sending crafted TCP pa... |
| CVE-2024-13150 | CRITICAL | 9.8 | 0.3% | Sep 29, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Fayton Software an... |
| CVE-2024-5200 | MEDIUM | 4.8 | 0.2% | Sep 29, 2025 | The Postie WordPress plugin before 1.9.71 does not sanitise and escape some of its settings, which could allow high priv... |
| CVE-2024-43192 | HIGH | 8.8 | 0.2% | Sep 27, 2025 | IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site request forgery which could allow an attack... |
| CVE-2024-48014 | HIGH | 7.5 | 0.3% | Sep 25, 2025 | Dell BSAFE Micro Edition Suite, versions prior to 5.0.2.3 contain an Out-of-bounds Write vulnerability. An unauthenticat... |
| CVE-2024-58241 | MEDIUM | 5.5 | 0.1% | Sep 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Disable works on hci_unregiste... |
| CVE-2024-21935 | MEDIUM | 5 | 0.2% | Sep 23, 2025 | Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to manipulate R... |
| CVE-2024-21927 | MEDIUM | 5 | 0.3% | Sep 23, 2025 | Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to use certain ... |
| CVE-2024-6429 | MEDIUM | 4.3 | 0.2% | Sep 23, 2025 | A content spoofing vulnerability exists in multiple WSO2 products due to improper error message handling. Under certain ... |
| CVE-2024-4598 | MEDIUM | 6.5 | 0.3% | Sep 23, 2025 | An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich me... |
| CVE-2024-10246 | — | — | — | Sep 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now