2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57708 | MEDIUM | 5.7 | 0.9% | Jun 25, 2025 | An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __... |
| CVE-2024-27685 | HIGH | 7.1 | 0.3% | Jun 25, 2025 | SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote attacker to obtain sensi... |
| CVE-2024-51984 | MEDIUM | 6.8 | 0.8% | Jun 25, 2025 | An authenticated attacker can reconfigure the target device to use an external service (such as LDAP or FTP) controlled ... |
| CVE-2024-51983 | HIGH | 7.5 | 7.5% | Jun 25, 2025 | An unauthenticated attacker who can connect to the Web Services feature (HTTP TCP port 80) can issue a WS-Scan SOAP requ... |
| CVE-2024-51982 | HIGH | 7.5 | 6.8% | Jun 25, 2025 | An unauthenticated attacker who can connect to TCP port 9100 can issue a Printer Job Language (PJL) command that will cr... |
| CVE-2024-51981 | MEDIUM | 5.3 | 0.8% | Jun 25, 2025 | An unauthenticated attacker may perform a blind server side request forgery (SSRF), due to a CLRF injection issue that c... |
| CVE-2024-51980 | MEDIUM | 5.3 | 0.9% | Jun 25, 2025 | An unauthenticated attacker may perform a limited server side request forgery (SSRF), forcing the target device to open ... |
| CVE-2024-51979 | HIGH | 7.2 | 1.1% | Jun 25, 2025 | An authenticated attacker may trigger a stack based buffer overflow by performing a malformed request to either the HTTP... |
| CVE-2024-51978 | CRITICAL | 9.8 | 23.6% | Jun 25, 2025 | An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password... |
| CVE-2024-51977 | MEDIUM | 5.3 | 76.6% | Jun 25, 2025 | An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or t... |
| CVE-2024-56917 | HIGH | 7.1 | 0.3% | Jun 24, 2025 | Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode. |
| CVE-2024-37743 | CRITICAL | 9.8 | 0.6% | Jun 24, 2025 | An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Comp... |
| CVE-2024-56916 | MEDIUM | 6.1 | 0.3% | Jun 24, 2025 | In Netbox Community 4.1.7, once authenticated, Configuration History > Add`is vulnerable to cross-site scripting (XSS) d... |
| CVE-2024-56918 | MEDIUM | 6.1 | 0.3% | Jun 24, 2025 | In Netbox Community 4.1.7, the login page is vulnerable to cross-site scripting (XSS), which allows a privileged, authen... |
| CVE-2024-56731 | CRITICAL | 9.8 | 1.0% | Jun 24, 2025 | Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .... |
| CVE-2024-45347 | CRITICAL | 9.6 | 0.2% | Jun 23, 2025 | An unauthorized access vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the val... |
| CVE-2024-3511 | MEDIUM | 4.3 | 0.2% | Jun 23, 2025 | An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned f... |
| CVE-2024-4994 | HIGH | 8.1 | 0.4% | Jun 20, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting fr... |
| CVE-2024-4025 | HIGH | 7.5 | 0.5% | Jun 20, 2025 | A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16... |
| CVE-2024-7586 | HIGH | 7.5 | 0.3% | Jun 20, 2025 | An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior... |
| CVE-2024-53298 | CRITICAL | 9.8 | 0.5% | Jun 20, 2025 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains a missing authorization vulnerability in the NFS expo... |
| CVE-2024-24916 | HIGH | 7.8 | 1.8% | Jun 19, 2025 | Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution ... |
| CVE-2024-45208 | CRITICAL | 9.8 | 0.7% | Jun 19, 2025 | The Versa Director SD-WAN orchestration platform which makes use of Cisco NCS application service. Active and Standby Di... |
| CVE-2024-54172 | MEDIUM | 4.3 | 0.1% | Jun 18, 2025 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnera... |
| CVE-2024-54183 | MEDIUM | 5.4 | 0.2% | Jun 18, 2025 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnera... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now