2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12914 | MEDIUM | 4.3 | 0.2% | Sep 1, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akınsoft QR... |
| CVE-2024-32832 | CRITICAL | 9.8 | 0.3% | Aug 31, 2025 | Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects L... |
| CVE-2024-32589 | HIGH | 7.1 | 0.2% | Aug 31, 2025 | Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager ... |
| CVE-2024-46484 | CRITICAL | 9.8 | 1.1% | Aug 29, 2025 | TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the /server/cgi-bin/testser... |
| CVE-2024-12923 | MEDIUM | 5.4 | 0.2% | Aug 29, 2025 | A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If a remote attacker gains a user ... |
| CVE-2024-46917 | HIGH | 8.1 | 0.2% | Aug 29, 2025 | Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR01 does not validate file attributes or the contents of /root dur... |
| CVE-2024-46916 | HIGH | 8.1 | 0.3% | Aug 29, 2025 | Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical sys... |
| CVE-2024-13342 | CRITICAL | 9.8 | 0.7% | Aug 29, 2025 | The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida... |
| CVE-2024-13987 | MEDIUM | 5.9 | 0.3% | Aug 29, 2025 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Synology RADIUS Se... |
| CVE-2024-54568 | MEDIUM | 4.3 | 0.2% | Aug 29, 2025 | The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. Parsing a maliciously ... |
| CVE-2024-54554 | MEDIUM | 5.5 | 0.2% | Aug 29, 2025 | This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be ab... |
| CVE-2024-44271 | LOW | 3.3 | 0.1% | Aug 29, 2025 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to record th... |
| CVE-2024-13986 | HIGH | 8.8 | 1.7% | Aug 28, 2025 | Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload an... |
| CVE-2024-48908 | MEDIUM | 6.9 | 0.4% | Aug 28, 2025 | lychee link checking action checks links in Markdown, HTML, and text files using lychee. Prior to version 2.0.2, there i... |
| CVE-2024-49790 | MEDIUM | 5.4 | 0.2% | Aug 28, 2025 | IBM Watson Studio on Cloud Pak for Data 4.0 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows an ... |
| CVE-2024-58240 | HIGH | 7.8 | 0.3% | Aug 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: tls: separate no-async decryption request handling ... |
| CVE-2024-13807 | HIGH | 7.5 | 0.4% | Aug 28, 2025 | The Xagio SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,... |
| CVE-2024-9648 | MEDIUM | 6.1 | 0.2% | Aug 28, 2025 | The WP ULike Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation i... |
| CVE-2024-13985 | CRITICAL | 10 | 15.1% | Aug 27, 2025 | A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to exe... |
| CVE-2024-13984 | CRITICAL | 10 | 0.8% | Aug 27, 2025 | QiAnXin TianQing Management Center versions up to and including 6.7.0.4130 contain a path traversal vulnerability in the... |
| CVE-2024-13982 | HIGH | 8.7 | 1.0% | Aug 27, 2025 | SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON Communications, contains an ar... |
| CVE-2024-13981 | CRITICAL | 10 | 0.9% | Aug 27, 2025 | LiveBOS, an object-oriented business architecture middleware suite developed by Apex Software Co., Ltd., contains an arb... |
| CVE-2024-13980 | CRITICAL | 10 | 1.0% | Aug 27, 2025 | H3C Intelligent Management Center (IMC) versions up to and including E0632H07 contains a remote command execution vulner... |
| CVE-2024-13979 | CRITICAL | 9.8 | 2.9% | Aug 27, 2025 | A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenticated remote attackers ... |
| CVE-2024-37777 | HIGH | 8.8 | 0.5% | Aug 27, 2025 | O2OA v9.0.3 was discovered to contain a remote code execution (RCE) vulnerability via the mainOutput() function. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now