2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25176 | CRITICAL | 9.8 | 0.5% | Jul 7, 2025 | LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in lj_strfmt_wfnum in lj_strf... |
| CVE-2024-13786 | CRITICAL | 9.8 | 0.5% | Jul 2, 2025 | The education theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.6.10 via... |
| CVE-2024-12364 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mavi Yeşil Softwar... |
| CVE-2024-12150 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eron Software Woww... |
| CVE-2024-12143 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mobilteg Mobile In... |
| CVE-2024-11739 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Case Informatics C... |
| CVE-2024-12827 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | The DWT - Directory & Listing WordPress Theme theme for WordPress is vulnerable to privilege escalation via account take... |
| CVE-2024-51978 | CRITICAL | 9.8 | 23.6% | Jun 25, 2025 | An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password... |
| CVE-2024-37743 | CRITICAL | 9.8 | 0.6% | Jun 24, 2025 | An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Comp... |
| CVE-2024-56731 | CRITICAL | 9.8 | 1.0% | Jun 24, 2025 | Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .... |
| CVE-2024-45347 | CRITICAL | 9.6 | 0.2% | Jun 23, 2025 | An unauthorized access vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the val... |
| CVE-2024-53298 | CRITICAL | 9.8 | 0.5% | Jun 20, 2025 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains a missing authorization vulnerability in the NFS expo... |
| CVE-2024-45208 | CRITICAL | 9.8 | 0.7% | Jun 19, 2025 | The Versa Director SD-WAN orchestration platform which makes use of Cisco NCS application service. Active and Standby Di... |
| CVE-2024-56158 | CRITICAL | 9.8 | 0.4% | Jun 12, 2025 | XWiki is a generic wiki platform. It's possible to execute any SQL query in Oracle by using the function like DBMS_XMLGE... |
| CVE-2024-1244 | CRITICAL | 9.5 | 0.3% | Jun 11, 2025 | Improper input validation in the OSSEC HIDS agent for Windows prior to version 3.8.0 allows an attacker in with control ... |
| CVE-2024-1243 | CRITICAL | 9.5 | 0.5% | Jun 11, 2025 | Improper input validation in the Wazuh agent for Windows prior to version 4.8.0 allows an attacker with control over the... |
| CVE-2024-57190 | CRITICAL | 9.8 | 0.6% | Jun 10, 2025 | Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP... |
| CVE-2024-55585 | CRITICAL | 9 | 0.4% | Jun 7, 2025 | In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, re... |
| CVE-2024-22330 | CRITICAL | 9.8 | 0.3% | Jun 6, 2025 | IBM Security Verify Governance 10.0.2 does not require that users should have strong passwords by default, which makes i... |
| CVE-2024-13967 | CRITICAL | 9.4 | 0.4% | Jun 4, 2025 | This vulnerability allows the successful attacker to gain unauthorized access to a configuration web page delivered by ... |
| CVE-2024-42191 | CRITICAL | 9.8 | 0.2% | May 30, 2025 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker ... |
| CVE-2024-42190 | CRITICAL | 9.8 | 0.2% | May 30, 2025 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker ... |
| CVE-2024-51360 | CRITICAL | 9.8 | 0.8% | May 23, 2025 | An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor... |
| CVE-2024-51101 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | PHPGURUKUL Restaurant Table Booking System using PHP and MySQL v1.0 was discovered to contain a SQL injection vulnerabil... |
| CVE-2024-6914 | CRITICAL | 9.8 | 0.6% | May 22, 2025 | An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account re... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now