2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53286 | HIGH | 7.2 | 1.1% | Jul 23, 2025 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record ... |
| CVE-2024-38335 | MEDIUM | 4.5 | 0.2% | Jul 22, 2025 | IBM Security QRadar Network Threat Analytics 1.0.0 through 1.3.1 could allow a privileged user to cause a denial of serv... |
| CVE-2024-55040 | MEDIUM | 6.1 | 0.7% | Jul 21, 2025 | Cross Site Scripting vulnerability in Sensaphone WEB600 Monitoring System v.1.6.5.H and before allows a remote attacker ... |
| CVE-2024-13974 | HIGH | 8.1 | 6.7% | Jul 21, 2025 | A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead... |
| CVE-2024-13973 | HIGH | 7.2 | 8.3% | Jul 21, 2025 | A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR1 (21.0.1) can potenti... |
| CVE-2024-6107 | CRITICAL | 9.8 | 0.4% | Jul 21, 2025 | Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC c... |
| CVE-2024-13175 | MEDIUM | 5.5 | 0.1% | Jul 18, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Vidco Software VOC TESTER allows Forceful Browsing. T... |
| CVE-2024-32124 | MEDIUM | 4.3 | 0.3% | Jul 18, 2025 | An improper access control vulnerability [CWE-284] in FortiIsolator version 2.4.4, version 2.4.3, 2.3 all versions loggi... |
| CVE-2024-27779 | MEDIUM | 6.7 | 0.5% | Jul 18, 2025 | An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version... |
| CVE-2024-42209 | LOW | 3.5 | 0.2% | Jul 17, 2025 | HCL Connections is vulnerable to an information disclosure vulnerability that could allow a user to obtain sensitive inf... |
| CVE-2024-41921 | HIGH | 7.8 | 0.2% | Jul 17, 2025 | A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, aff... |
| CVE-2024-41148 | HIGH | 7.8 | 0.2% | Jul 17, 2025 | A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, aff... |
| CVE-2024-39835 | HIGH | 7.8 | 0.2% | Jul 17, 2025 | A code injection vulnerability has been identified in the Robot Operating System (ROS) 'roslaunch' command-line tool, af... |
| CVE-2024-39289 | HIGH | 7.8 | 0.2% | Jul 17, 2025 | A code execution vulnerability has been discovered in the Robot Operating System (ROS) 'rosparam' tool, affecting ROS di... |
| CVE-2024-13972 | HIGH | 8.8 | 0.1% | Jul 17, 2025 | A vulnerability related to registry permissions in the Intercept X for Windows updater prior to Core Agent version 2024.... |
| CVE-2024-32323 | HIGH | 8.1 | 0.3% | Jul 17, 2025 | SQL Injection vulnerability in cnhcit.com Haichang OA v.1.0.0 allows a remote attacker to obtain sensitive information v... |
| CVE-2024-12498 | — | — | — | Jul 16, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-42912 | MEDIUM | 5.4 | 0.2% | Jul 16, 2025 | A cross-site scripting (XSS) vulnerability in META-INF Kft. Email This Issue (Data Center) before 9.13.0-GA allows attac... |
| CVE-2024-9408 | CRITICAL | 9.8 | 0.3% | Jul 16, 2025 | In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endp... |
| CVE-2024-9343 | MEDIUM | 6.1 | 0.2% | Jul 16, 2025 | In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Con... |
| CVE-2024-9342 | CRITICAL | 9.8 | 0.4% | Jul 16, 2025 | In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation... |
| CVE-2024-10032 | MEDIUM | 5.4 | 0.2% | Jul 16, 2025 | In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Con... |
| CVE-2024-10031 | MEDIUM | 5.4 | 0.2% | Jul 16, 2025 | In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configur... |
| CVE-2024-10029 | MEDIUM | 6.1 | 0.2% | Jul 16, 2025 | In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration ... |
| CVE-2024-42650 | HIGH | 7.5 | 0.5% | Jul 15, 2025 | NanoMQ 0.17.5 was discovered to contain a segmentation fault via the component /nanomq/pub_handler.c. This vulnerability... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now