2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13984 | CRITICAL | 10 | 0.8% | Aug 27, 2025 | QiAnXin TianQing Management Center versions up to and including 6.7.0.4130 contain a path traversal vulnerability in the... |
| CVE-2024-13981 | CRITICAL | 10 | 0.8% | Aug 27, 2025 | LiveBOS, an object-oriented business architecture middleware suite developed by Apex Software Co., Ltd., contains an arb... |
| CVE-2024-13980 | CRITICAL | 10 | 1.2% | Aug 27, 2025 | H3C Intelligent Management Center (IMC) versions up to and including E0632H07 contains a remote command execution vulner... |
| CVE-2024-13979 | CRITICAL | 9.8 | 2.9% | Aug 27, 2025 | A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenticated remote attackers ... |
| CVE-2024-39335 | CRITICAL | 9.1 | 0.3% | Aug 26, 2025 | Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed... |
| CVE-2024-53499 | CRITICAL | 9.8 | 0.5% | Aug 22, 2025 | Jeewms v3.7 was discovered to contain a SQL injection vulnerability via the CgReportController API. |
| CVE-2024-53496 | CRITICAL | 9.8 | 0.5% | Aug 22, 2025 | Incorrect access control in the doFilter function of my-site v1.0.2.RELEASE allows attackers to access sensitive compone... |
| CVE-2024-52786 | CRITICAL | 9.8 | 0.8% | Aug 22, 2025 | An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute a... |
| CVE-2024-50645 | CRITICAL | 9.8 | 0.6% | Aug 22, 2025 | MallChat v1.0-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access ... |
| CVE-2024-50644 | CRITICAL | 9.8 | 0.5% | Aug 22, 2025 | zhisheng17 blog 3.0.1-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to... |
| CVE-2024-45438 | CRITICAL | 9.1 | 0.5% | Aug 21, 2025 | An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. Th... |
| CVE-2024-57155 | CRITICAL | 9.8 | 0.4% | Aug 20, 2025 | Incorrect access control in radar v1.0.8 allows attackers to bypass authentication and access sensitive APIs without a t... |
| CVE-2024-57154 | CRITICAL | 9.8 | 0.4% | Aug 20, 2025 | Incorrect access control in dts-shop v0.0.1-SNAPSHOT allows attackers to bypass authentication via sending a crafted pay... |
| CVE-2024-50640 | CRITICAL | 9.8 | 0.5% | Aug 20, 2025 | jeewx-boot 1.3 has an authentication bypass vulnerability in the preHandle function |
| CVE-2024-57157 | CRITICAL | 9.8 | 0.4% | Aug 20, 2025 | Incorrect access control in Jantent v1.1 allows attackers to bypass authentication and access sensitive APIs without a t... |
| CVE-2024-12223 | CRITICAL | 9.3 | 0.3% | Aug 20, 2025 | Prism Central versions prior to 2024.3.1 are vulnerable to a stored cross-site scripting attack via the Events component... |
| CVE-2024-44373 | CRITICAL | 9.8 | 1.1% | Aug 19, 2025 | A Path Traversal vulnerability in AllSky v2023.05.01 through v2024.12.06_06 allows an unauthenticated attacker to create... |
| CVE-2024-32640 | CRITICAL | 9.8 | 68.6% | Aug 11, 2025 | MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, ... |
| CVE-2024-58266 | CRITICAL | 9.8 | 0.8% | Jul 27, 2025 | The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may fa... |
| CVE-2024-6107 | CRITICAL | 9.8 | 0.4% | Jul 21, 2025 | Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC c... |
| CVE-2024-9408 | CRITICAL | 9.8 | 0.3% | Jul 16, 2025 | In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endp... |
| CVE-2024-9342 | CRITICAL | 9.8 | 0.4% | Jul 16, 2025 | In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation... |
| CVE-2024-39752 | CRITICAL | 9.8 | 0.3% | Jul 10, 2025 | IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by not validating the type... |
| CVE-2024-38327 | CRITICAL | 9.8 | 0.3% | Jul 10, 2025 | IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 is vulnerable to information exposure and further attacks due to an exp... |
| CVE-2024-25178 | CRITICAL | 9.1 | 0.5% | Jul 7, 2025 | LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler i... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now