2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-58261 | HIGH | 7.5 | 0.4% | Jul 27, 2025 | The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: N... |
| CVE-2024-13507 | HIGH | 7.5 | 0.4% | Jul 26, 2025 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to ... |
| CVE-2024-13976 | HIGH | 8.5 | 0.2% | Jul 25, 2025 | A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During th... |
| CVE-2024-13975 | HIGH | 8.5 | 0.1% | Jul 25, 2025 | A local privilege escalation vulnerability exists in Commvault for Windows versions 11.20.0, 11.28.0, 11.32.0, 11.34.0, ... |
| CVE-2024-48730 | MEDIUM | 6.5 | 0.5% | Jul 25, 2025 | The default configuration in ETSI Open-Source MANO (OSM) v.14.x, v.15.x, v.16.x, v.17.x does not impose any restrictions... |
| CVE-2024-48729 | HIGH | 7.1 | 0.3% | Jul 25, 2025 | An issue in ETSI Open-Source MANO (OSM) 14.0.x before 14.0.3, 15.0.x before 15.0.2, 16.0.0, and 17.0.0 allows a remote a... |
| CVE-2024-41751 | MEDIUM | 5.5 | 0.1% | Jul 23, 2025 | IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, au... |
| CVE-2024-41750 | MEDIUM | 5.5 | 0.1% | Jul 23, 2025 | IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, au... |
| CVE-2024-40686 | MEDIUM | 6.1 | 0.2% | Jul 23, 2025 | IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 is vulnerable to HTTP h... |
| CVE-2024-40682 | MEDIUM | 5.5 | 0.1% | Jul 23, 2025 | IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local use... |
| CVE-2024-12310 | HIGH | 7 | 0.2% | Jul 23, 2025 | A vulnerability in Imprivata Enterprise Access Management (formerly Imprivata OneSign) allows bypassing the login screen... |
| CVE-2024-53288 | MEDIUM | 5.9 | 0.2% | Jul 23, 2025 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in NTP Region functio... |
| CVE-2024-53287 | MEDIUM | 5.9 | 0.2% | Jul 23, 2025 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functi... |
| CVE-2024-53286 | HIGH | 7.2 | 1.1% | Jul 23, 2025 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record ... |
| CVE-2024-38335 | MEDIUM | 4.5 | 0.2% | Jul 22, 2025 | IBM Security QRadar Network Threat Analytics 1.0.0 through 1.3.1 could allow a privileged user to cause a denial of serv... |
| CVE-2024-55040 | MEDIUM | 6.1 | 0.7% | Jul 21, 2025 | Cross Site Scripting vulnerability in Sensaphone WEB600 Monitoring System v.1.6.5.H and before allows a remote attacker ... |
| CVE-2024-13974 | HIGH | 8.1 | 6.7% | Jul 21, 2025 | A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead... |
| CVE-2024-13973 | HIGH | 7.2 | 8.3% | Jul 21, 2025 | A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR1 (21.0.1) can potenti... |
| CVE-2024-6107 | CRITICAL | 9.8 | 0.4% | Jul 21, 2025 | Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC c... |
| CVE-2024-13175 | MEDIUM | 5.5 | 0.1% | Jul 18, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Vidco Software VOC TESTER allows Forceful Browsing. T... |
| CVE-2024-32124 | MEDIUM | 4.3 | 0.3% | Jul 18, 2025 | An improper access control vulnerability [CWE-284] in FortiIsolator version 2.4.4, version 2.4.3, 2.3 all versions loggi... |
| CVE-2024-27779 | MEDIUM | 6.7 | 0.5% | Jul 18, 2025 | An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version... |
| CVE-2024-42209 | LOW | 3.5 | 0.2% | Jul 17, 2025 | HCL Connections is vulnerable to an information disclosure vulnerability that could allow a user to obtain sensitive inf... |
| CVE-2024-41921 | HIGH | 7.8 | 0.2% | Jul 17, 2025 | A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, aff... |
| CVE-2024-41148 | HIGH | 7.8 | 0.2% | Jul 17, 2025 | A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, aff... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now