2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43706 | HIGH | 8.8 | 0.3% | Jun 10, 2025 | Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint. |
| CVE-2024-32119 | MEDIUM | 4.8 | 0.3% | Jun 10, 2025 | An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an u... |
| CVE-2024-41797 | MEDIUM | 5.3 | 0.3% | Jun 10, 2025 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.1), SCALANCE XC316-8 (6GK53... |
| CVE-2024-40625 | MEDIUM | 4.9 | 0.3% | Jun 10, 2025 | GeoServer is an open source server that allows users to share and edit geospatial data. The Coverage rest api /workspace... |
| CVE-2024-38524 | HIGH | 7.5 | 0.4% | Jun 10, 2025 | GeoServer is an open source server that allows users to share and edit geospatial data. org.geowebcache.GeoWebCacheDispa... |
| CVE-2024-34711 | HIGH | 8.2 | 0.3% | Jun 10, 2025 | GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulne... |
| CVE-2024-29198 | HIGH | 8.2 | 1.9% | Jun 10, 2025 | GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. It poss... |
| CVE-2024-13090 | HIGH | 7.3 | 0.1% | Jun 10, 2025 | A privilege escalation vulnerability may enable a service account to elevate its privileges. The sudo rules configure... |
| CVE-2024-13089 | HIGH | 7.5 | 1.0% | Jun 10, 2025 | An OS command injection vulnerability within the update functionality may allow an authenticated administrator to execut... |
| CVE-2024-55595 | — | — | — | Jun 10, 2025 | Rejected reason: Not used |
| CVE-2024-47081 | MEDIUM | 5.3 | 0.8% | Jun 9, 2025 | Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to... |
| CVE-2024-46452 | MEDIUM | 6.1 | 0.3% | Jun 9, 2025 | A Host Header injection vulnerability in the password reset function of VigyBag Open Source Online Shop commit 3f0e21b a... |
| CVE-2024-55585 | CRITICAL | 9 | 0.4% | Jun 7, 2025 | In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, re... |
| CVE-2024-9994 | MEDIUM | 5.4 | 0.2% | Jun 7, 2025 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for Wo... |
| CVE-2024-9993 | MEDIUM | 5.4 | 0.2% | Jun 7, 2025 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for Wo... |
| CVE-2024-56805 | MEDIUM | 5.4 | 0.4% | Jun 6, 2025 | A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vu... |
| CVE-2024-50406 | MEDIUM | 5.4 | 0.2% | Jun 6, 2025 | A cross-site scripting (XSS) vulnerability has been reported to affect License Center. If exploited, the vulnerability c... |
| CVE-2024-13088 | HIGH | 7.8 | 0.2% | Jun 6, 2025 | An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, t... |
| CVE-2024-13087 | MEDIUM | 6.7 | 0.6% | Jun 6, 2025 | A command injection vulnerability has been reported to affect QHora. If an attacker gains local network access who have ... |
| CVE-2024-58114 | MEDIUM | 4 | 0.1% | Jun 6, 2025 | Resource allocation control failure vulnerability in the ArkUI framework Impact: Successful exploitation of this vulnera... |
| CVE-2024-46941 | MEDIUM | 4.8 | 0.1% | Jun 6, 2025 | SystemUI has an incorrect component protection setting, which allows access to specific information. |
| CVE-2024-56343 | MEDIUM | 6.5 | 0.3% | Jun 6, 2025 | IBM Verify Identity Access Digital Credentials 24.06 could allow an authenticated user to crash the service with a speci... |
| CVE-2024-56342 | MEDIUM | 5.3 | 0.3% | Jun 6, 2025 | IBM Verify Identity Access Digital Credentials 24.06 could allow a remote attacker to obtain sensitive information when ... |
| CVE-2024-22330 | CRITICAL | 9.8 | 0.3% | Jun 6, 2025 | IBM Security Verify Governance 10.0.2 does not require that users should have strong passwords by default, which makes i... |
| CVE-2024-13967 | CRITICAL | 9.4 | 0.4% | Jun 4, 2025 | This vulnerability allows the successful attacker to gain unauthorized access to a configuration web page delivered by ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now