2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-58308 | CRITICAL | 9.8 | 0.6% | Dec 11, 2025 | Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authenticatio... |
| CVE-2024-58301 | CRITICAL | 9.3 | 0.3% | Dec 11, 2025 | Purei CMS 1.0 contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queri... |
| CVE-2024-58298 | CRITICAL | 9.2 | 1.0% | Dec 11, 2025 | Compuware iStrobe Web 20.13 contains a pre-authentication remote code execution vulnerability that allows unauthenticate... |
| CVE-2024-58290 | CRITICAL | 9.3 | 0.4% | Dec 11, 2025 | Xhibiter NFT Marketplace 1.10.2 contains a SQL injection vulnerability in the collections endpoint that allows attackers... |
| CVE-2024-58286 | CRITICAL | 9.3 | 0.6% | Dec 11, 2025 | dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through... |
| CVE-2024-45538 | CRITICAL | 9.6 | 0.4% | Dec 4, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-6... |
| CVE-2024-32641 | CRITICAL | 9.8 | 12.3% | Dec 3, 2025 | Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 a... |
| CVE-2024-5539 | CRITICAL | 9.2 | 0.3% | Nov 27, 2025 | The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows... |
| CVE-2024-47856 | CRITICAL | 9.8 | 0.5% | Nov 24, 2025 | In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the... |
| CVE-2024-44659 | CRITICAL | 9.8 | 0.4% | Nov 17, 2025 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php. |
| CVE-2024-14003 | CRITICAL | 9.8 | 2.3% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data ... |
| CVE-2024-13999 | CRITICAL | 9.8 | 1.9% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP... |
| CVE-2024-13996 | CRITICAL | 9.8 | 1.1% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password... |
| CVE-2024-13994 | CRITICAL | 9.8 | 0.9% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option i... |
| CVE-2024-45162 | CRITICAL | 9.8 | 0.5% | Oct 29, 2025 | A stack-based buffer overflow issue was discovered in the phddns client in Blu-Castle BCUM221E 1.0.0P220507 via the pass... |
| CVE-2024-33507 | CRITICAL | 9.1 | 0.4% | Oct 14, 2025 | An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in For... |
| CVE-2024-58040 | CRITICAL | 9.1 | 0.2% | Sep 30, 2025 | Crypt::RandomEncryption for Perl version 0.01 uses insecure rand() function during encryption. |
| CVE-2024-13150 | CRITICAL | 9.8 | 0.3% | Sep 29, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Fayton Software an... |
| CVE-2024-13990 | CRITICAL | 9.3 | 0.6% | Sep 19, 2025 | MicroWorld eScan AV's update mechanism failed to ensure authenticity and integrity of updates: update packages were deli... |
| CVE-2024-13151 | CRITICAL | 9.8 | 0.3% | Sep 18, 2025 | CWE - 89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ESBI In... |
| CVE-2024-13149 | CRITICAL | 9.8 | 0.4% | Sep 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive ... |
| CVE-2024-45434 | CRITICAL | 9.8 | 5.9% | Sep 12, 2025 | OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetoo... |
| CVE-2024-43166 | CRITICAL | 9.8 | 0.5% | Sep 3, 2025 | Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: bef... |
| CVE-2024-32444 | CRITICAL | 9.8 | 0.6% | Sep 3, 2025 | Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue... |
| CVE-2024-28988 | CRITICAL | 9.8 | 36.6% | Sep 1, 2025 | SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that,... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now