2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-58286 | CRITICAL | 9.3 | 0.5% | Dec 11, 2025 | dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through... |
| CVE-2024-45538 | CRITICAL | 9.6 | 0.3% | Dec 4, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-6... |
| CVE-2024-32641 | CRITICAL | 9.8 | 10.6% | Dec 3, 2025 | Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 a... |
| CVE-2024-5539 | CRITICAL | 9.2 | 0.3% | Nov 27, 2025 | The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows... |
| CVE-2024-47856 | CRITICAL | 9.8 | 0.5% | Nov 24, 2025 | In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the... |
| CVE-2024-44659 | CRITICAL | 9.8 | 0.4% | Nov 17, 2025 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php. |
| CVE-2024-14003 | CRITICAL | 9.8 | 2.1% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data ... |
| CVE-2024-13999 | CRITICAL | 9.8 | 1.8% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP... |
| CVE-2024-13996 | CRITICAL | 9.8 | 1.0% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password... |
| CVE-2024-13994 | CRITICAL | 9.8 | 0.8% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option i... |
| CVE-2024-45162 | CRITICAL | 9.8 | 0.5% | Oct 29, 2025 | A stack-based buffer overflow issue was discovered in the phddns client in Blu-Castle BCUM221E 1.0.0P220507 via the pass... |
| CVE-2024-33507 | CRITICAL | 9.1 | 0.4% | Oct 14, 2025 | An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in For... |
| CVE-2024-58040 | CRITICAL | 9.1 | 0.2% | Sep 30, 2025 | Crypt::RandomEncryption for Perl version 0.01 uses insecure rand() function during encryption. |
| CVE-2024-13150 | CRITICAL | 9.8 | 0.3% | Sep 29, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Fayton Software an... |
| CVE-2024-13990 | CRITICAL | 9.3 | 0.6% | Sep 19, 2025 | MicroWorld eScan AV's update mechanism failed to ensure authenticity and integrity of updates: update packages were deli... |
| CVE-2024-13151 | CRITICAL | 9.8 | 0.3% | Sep 18, 2025 | CWE - 89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ESBI In... |
| CVE-2024-13149 | CRITICAL | 9.8 | 0.4% | Sep 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive ... |
| CVE-2024-45434 | CRITICAL | 9.8 | 5.9% | Sep 12, 2025 | OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetoo... |
| CVE-2024-43166 | CRITICAL | 9.8 | 0.5% | Sep 3, 2025 | Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: bef... |
| CVE-2024-32444 | CRITICAL | 9.8 | 0.6% | Sep 3, 2025 | Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue... |
| CVE-2024-28988 | CRITICAL | 9.8 | 36.6% | Sep 1, 2025 | SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that,... |
| CVE-2024-32832 | CRITICAL | 9.8 | 0.3% | Aug 31, 2025 | Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects L... |
| CVE-2024-46484 | CRITICAL | 9.8 | 1.1% | Aug 29, 2025 | TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the /server/cgi-bin/testser... |
| CVE-2024-13342 | CRITICAL | 9.8 | 0.7% | Aug 29, 2025 | The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida... |
| CVE-2024-13985 | CRITICAL | 10 | 7.7% | Aug 27, 2025 | A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to exe... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now