2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13995 | HIGH | 8.8 | 1.3% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive user account inform... |
| CVE-2024-13994 | CRITICAL | 9.8 | 0.9% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option i... |
| CVE-2024-13993 | MEDIUM | 6.1 | 0.8% | Oct 30, 2025 | Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) via the login page whe... |
| CVE-2024-14012 | HIGH | 7.3 | 0.1% | Oct 29, 2025 | Potential privilege escalation issue in Revenera InstallShield version 2023 R1 running a renamed Setup.exe on Windows. W... |
| CVE-2024-58269 | MEDIUM | 4.3 | 0.3% | Oct 29, 2025 | A vulnerability has been identified in Rancher Manager, where sensitive information, including secret data, cluster imp... |
| CVE-2024-45162 | CRITICAL | 9.8 | 0.5% | Oct 29, 2025 | A stack-based buffer overflow issue was discovered in the phddns client in Blu-Castle BCUM221E 1.0.0P220507 via the pass... |
| CVE-2024-45161 | MEDIUM | 4.6 | 0.1% | Oct 29, 2025 | A CSRF issue was discovered in the administrative web GUI in Blu-Castle BCUM221E 1.0.0P220507. This can be exploited via... |
| CVE-2024-14011 | — | — | — | Oct 23, 2025 | Rejected reason: This is a duplicate. |
| CVE-2024-58274 | HIGH | 8.3 | 19.1% | Oct 22, 2025 | Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a comm... |
| CVE-2024-55568 | HIGH | 7.5 | 0.5% | Oct 20, 2025 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128... |
| CVE-2024-31573 | MEDIUM | 4 | 0.2% | Oct 17, 2025 | XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (us... |
| CVE-2024-42192 | MEDIUM | 5.5 | 0.2% | Oct 16, 2025 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access... |
| CVE-2024-56143 | HIGH | 8.2 | 0.4% | Oct 16, 2025 | Strapi is an open-source headless content management system. In versions from 5.0.0 to before 5.5.2, the lookup operator... |
| CVE-2024-13991 | HIGH | 8.7 | 0.5% | Oct 15, 2025 | Huijietong Cloud Video Platform contains a path traversal vulnerability that allows an unauthenticated attacker can supp... |
| CVE-2024-50571 | HIGH | 7.2 | 0.5% | Oct 14, 2025 | A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.... |
| CVE-2024-48891 | HIGH | 7 | 0.5% | Oct 14, 2025 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in ... |
| CVE-2024-47569 | MEDIUM | 4.3 | 0.4% | Oct 14, 2025 | A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7... |
| CVE-2024-33507 | CRITICAL | 9.1 | 0.4% | Oct 14, 2025 | An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in For... |
| CVE-2024-26008 | MEDIUM | 5.3 | 0.4% | Oct 14, 2025 | An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 a... |
| CVE-2024-44088 | MEDIUM | 6.1 | 0.6% | Oct 14, 2025 | Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability all... |
| CVE-2024-6211 | — | — | — | Oct 13, 2025 | Rejected reason: loading template... |
| CVE-2024-56804 | HIGH | 8.8 | 0.3% | Oct 3, 2025 | An SQL injection vulnerability has been reported to affect Video Station. If a remote attacker gains a user account, the... |
| CVE-2024-58267 | HIGH | 8 | 0.2% | Oct 2, 2025 | A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI tool is... |
| CVE-2024-58260 | HIGH | 7.6 | 0.5% | Oct 2, 2025 | A vulnerability has been identified within Rancher Manager where a missing server-side validation on the `.username` fie... |
| CVE-2024-57494 | MEDIUM | 6.5 | 0.3% | Oct 1, 2025 | Cross Site Scripting vulnerability in Neto E-Commerce CMS v.6.313.0 through v.6.3115 allows a remote attacker to escalat... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now