2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-58348 | CRITICAL | 9.8 | 0.8% | Jun 8, 2026 | WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticate... |
| CVE-2024-27892 | CRITICAL | 9.6 | 0.3% | Jun 4, 2026 | Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been... |
| CVE-2024-27891 | MEDIUM | 6.9 | 0.3% | Jun 4, 2026 | On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies... |
| CVE-2024-27890 | CRITICAL | 9.6 | 4.4% | Jun 4, 2026 | Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been... |
| CVE-2024-6858 | MEDIUM | 6.5 | 0.1% | Jun 4, 2026 | In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there ... |
| CVE-2024-47273 | MEDIUM | 4.3 | 0.3% | Jun 3, 2026 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functiona... |
| CVE-2024-47263 | MEDIUM | 4.1 | 0.3% | Jun 3, 2026 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository web... |
| CVE-2024-14036 | HIGH | 8.7 | 0.3% | Jun 2, 2026 | Dräger Core 1.0.5 and Dräger M540 Converter Service 1.0.9 contain a denial of service vulnerability that allows network-... |
| CVE-2024-42206 | LOW | 3.1 | 0.2% | Jun 2, 2026 | HCL iReflection Third party vulnerable and outdated components issue was detected in the web application |
| CVE-2024-52011 | HIGH | 8.3 | 0.5% | Jun 1, 2026 | launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the in... |
| CVE-2024-40646 | HIGH | 8.6 | 0.4% | Jun 1, 2026 | Vertex is a management tool for PT (Private Tracker) users to manage streaming and watching videos. Versions prior to co... |
| CVE-2024-47097 | MEDIUM | 5.1 | 0.3% | May 28, 2026 | Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run... |
| CVE-2024-47096 | MEDIUM | 5.1 | 0.3% | May 28, 2026 | Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run... |
| CVE-2024-56462 | HIGH | 8.8 | 0.5% | May 27, 2026 | IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive t... |
| CVE-2024-40684 | CRITICAL | 9.8 | 0.4% | May 27, 2026 | IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2,... |
| CVE-2024-28765 | MEDIUM | 5.3 | 0.4% | May 27, 2026 | IBM SDI 7.2.0.0 through 7.2.0.14 and IBM Security Directory Integrator 10.0.0.0 through 10.0.0.2 could allow a remote at... |
| CVE-2024-47272 | LOW | 2.7 | 0.2% | May 27, 2026 | Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and... |
| CVE-2024-47271 | MEDIUM | 4.9 | 0.3% | May 27, 2026 | Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-... |
| CVE-2024-47270 | LOW | 2.7 | 0.2% | May 27, 2026 | Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station befo... |
| CVE-2024-47269 | MEDIUM | 4.9 | 0.2% | May 27, 2026 | Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Stati... |
| CVE-2024-47268 | MEDIUM | 4.9 | 0.3% | May 27, 2026 | Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.... |
| CVE-2024-47267 | LOW | 2.7 | 0.3% | May 27, 2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functiona... |
| CVE-2024-11399 | MEDIUM | 6.8 | 0.1% | May 27, 2026 | Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for des... |
| CVE-2024-36343 | MEDIUM | 4.6 | 0.2% | May 19, 2026 | Improper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to... |
| CVE-2024-36334 | HIGH | 7 | 0.1% | May 15, 2026 | Improper verification of cryptographic signature in the Radeon RGB tool could allow a malicious file placed in the insta... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now