2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-58344 | MEDIUM | 6.4 | 0.2% | Apr 22, 2026 | Carbon Forum 5.9.0 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to ... |
| CVE-2024-58343 | MEDIUM | 4.3 | 0.2% | Apr 16, 2026 | Vision Helpdesk before 5.7.0 (patched in 5.6.10) allows attackers to read user profiles via modified serialized cookie d... |
| CVE-2024-4867 | MEDIUM | 5.4 | 0.2% | Apr 16, 2026 | The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or p... |
| CVE-2024-10242 | MEDIUM | 6.1 | 0.2% | Apr 16, 2026 | The authentication endpoint fails to adequately validate user-supplied input before reflecting it back in the response. ... |
| CVE-2024-23104 | MEDIUM | 4.3 | 0.3% | Apr 14, 2026 | An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 t... |
| CVE-2024-53828 | MEDIUM | 5.3 | 0.4% | Apr 1, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a vulnerability where an attacker sending a large v... |
| CVE-2024-58342 | MEDIUM | 6.1 | 0.1% | Apr 1, 2026 | XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does... |
| CVE-2024-14028 | MEDIUM | 6.5 | 0.2% | Mar 27, 2026 | Use after free vulnerability in Softing smartLink HW-DP or smartLink HW-PN webserver allows HTTP DoS. This issue affects... |
| CVE-2024-46879 | MEDIUM | 5.4 | 0.2% | Mar 23, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system.php in... |
| CVE-2024-46878 | MEDIUM | 5.4 | 0.2% | Mar 23, 2026 | A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and ea... |
| CVE-2024-51226 | MEDIUM | 6.1 | 0.2% | Mar 23, 2026 | A stored cross-site scripting (XSS) vulnerability in the component /admin/search-vehicle.php of Phpgurukul Vehicle Recor... |
| CVE-2024-51225 | MEDIUM | 4.8 | 0.2% | Mar 23, 2026 | A stored cross-site scripting (XSS) vulnerability in the component /admin/add-brand.php of Phpgurukul Vehicle Record Man... |
| CVE-2024-51224 | MEDIUM | 4.8 | 0.2% | Mar 23, 2026 | Multiple cross-site scripting (XSS) vulnerabilities in the component /admin/edit-vehicle.php of Phpgurukul Vehicle Recor... |
| CVE-2024-51223 | MEDIUM | 4.8 | 0.2% | Mar 23, 2026 | A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Manag... |
| CVE-2024-51222 | MEDIUM | 4.8 | 0.2% | Mar 23, 2026 | A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Manag... |
| CVE-2024-13785 | MEDIUM | 5.6 | 0.3% | Mar 21, 2026 | The The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to arbitrary shortc... |
| CVE-2024-31119 | MEDIUM | 5.9 | 0.2% | Mar 20, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Vasilis Triantafyl... |
| CVE-2024-42210 | MEDIUM | 5.4 | 0.2% | Mar 19, 2026 | A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower. Stored cros... |
| CVE-2024-14025 | MEDIUM | 6.7 | 0.1% | Mar 11, 2026 | An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who ... |
| CVE-2024-14024 | MEDIUM | 6.7 | 0.1% | Mar 11, 2026 | An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local n... |
| CVE-2024-14027 | MEDIUM | 5.5 | 0.3% | Mar 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/xattr: missing fdput() in fremovexattr error pat... |
| CVE-2024-35644 | MEDIUM | 5.9 | 0.2% | Mar 6, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pascal Birc... |
| CVE-2024-43035 | MEDIUM | 5.8 | 2.4% | Mar 5, 2026 | Fonoster 0.5.5 before 0.6.1 allows ../ directory traversal to read arbitrary files via the /sounds/:file or /tts/:file V... |
| CVE-2024-55025 | MEDIUM | 6.5 | 0.3% | Mar 3, 2026 | Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized a... |
| CVE-2024-55023 | MEDIUM | 5.3 | 0.2% | Mar 3, 2026 | Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now