2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-24915 | HIGH | 7.2 | 0.2% | Jun 29, 2025 | Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump ... |
| CVE-2024-52900 | MEDIUM | 5.4 | 0.2% | Jun 28, 2025 | IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scrip... |
| CVE-2024-39730 | MEDIUM | 5.4 | 0.2% | Jun 28, 2025 | IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim.... |
| CVE-2024-36347 | MEDIUM | 6.4 | 0.1% | Jun 27, 2025 | Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator pri... |
| CVE-2024-12364 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mavi Yeşil Softwar... |
| CVE-2024-12150 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eron Software Woww... |
| CVE-2024-12143 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mobilteg Mobile In... |
| CVE-2024-11739 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Case Informatics C... |
| CVE-2024-12827 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | The DWT - Directory & Listing WordPress Theme theme for WordPress is vulnerable to privilege escalation via account take... |
| CVE-2024-52928 | HIGH | 8.3 | 0.4% | Jun 26, 2025 | Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permi... |
| CVE-2024-56915 | MEDIUM | 6.5 | 0.4% | Jun 26, 2025 | Netbox Community v4.1.7 and fixed in v.4.2.2 is vulnerable to Cross Site Scripting (XSS) via the RSS feed widget. |
| CVE-2024-6174 | HIGH | 8.8 | 0.2% | Jun 26, 2025 | When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To preven... |
| CVE-2024-11584 | MEDIUM | 5.3 | 0.1% | Jun 26, 2025 | cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grant... |
| CVE-2024-57708 | MEDIUM | 5.7 | 0.9% | Jun 25, 2025 | An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __... |
| CVE-2024-27685 | HIGH | 7.1 | 0.3% | Jun 25, 2025 | SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote attacker to obtain sensi... |
| CVE-2024-51984 | MEDIUM | 6.8 | 0.8% | Jun 25, 2025 | An authenticated attacker can reconfigure the target device to use an external service (such as LDAP or FTP) controlled ... |
| CVE-2024-51983 | HIGH | 7.5 | 7.5% | Jun 25, 2025 | An unauthenticated attacker who can connect to the Web Services feature (HTTP TCP port 80) can issue a WS-Scan SOAP requ... |
| CVE-2024-51982 | HIGH | 7.5 | 6.8% | Jun 25, 2025 | An unauthenticated attacker who can connect to TCP port 9100 can issue a Printer Job Language (PJL) command that will cr... |
| CVE-2024-51981 | MEDIUM | 5.3 | 0.8% | Jun 25, 2025 | An unauthenticated attacker may perform a blind server side request forgery (SSRF), due to a CLRF injection issue that c... |
| CVE-2024-51980 | MEDIUM | 5.3 | 0.9% | Jun 25, 2025 | An unauthenticated attacker may perform a limited server side request forgery (SSRF), forcing the target device to open ... |
| CVE-2024-51979 | HIGH | 7.2 | 1.1% | Jun 25, 2025 | An authenticated attacker may trigger a stack based buffer overflow by performing a malformed request to either the HTTP... |
| CVE-2024-51978 | CRITICAL | 9.8 | 23.6% | Jun 25, 2025 | An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password... |
| CVE-2024-51977 | MEDIUM | 5.3 | 76.6% | Jun 25, 2025 | An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or t... |
| CVE-2024-56917 | HIGH | 7.1 | 0.3% | Jun 24, 2025 | Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode. |
| CVE-2024-37743 | CRITICAL | 9.8 | 0.6% | Jun 24, 2025 | An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Comp... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now