2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-30855 | HIGH | 8.8 | 0.2% | Dec 29, 2025 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_act... |
| CVE-2024-9684 | HIGH | 7.5 | 0.3% | Dec 23, 2025 | FreyrSCADA/IEC-60870-5-104 server v21.06.008 allows remote attackers to cause a denial of service by sending specific me... |
| CVE-2024-24844 | HIGH | 7.5 | 0.2% | Dec 23, 2025 | Missing Authorization vulnerability in IdeaBox Creations PowerPack Pro for Elementor allows Exploiting Incorrectly Confi... |
| CVE-2024-46062 | HIGH | 7.8 | 0.2% | Dec 17, 2025 | Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside t... |
| CVE-2024-46060 | HIGH | 7.8 | 0.2% | Dec 17, 2025 | Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside th... |
| CVE-2024-29371 | HIGH | 7.5 | 0.2% | Dec 17, 2025 | In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encry... |
| CVE-2024-44599 | HIGH | 8.3 | 0.4% | Dec 15, 2025 | FNT Command 13.4.0 is vulnerable to Directory Traversal. |
| CVE-2024-44598 | HIGH | 8.8 | 0.4% | Dec 15, 2025 | FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module. |
| CVE-2024-58316 | HIGH | 8.7 | 0.5% | Dec 12, 2025 | Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows... |
| CVE-2024-58314 | HIGH | 8.8 | 1.4% | Dec 12, 2025 | Atcom 100M IP Phones firmware version 2.7.x.x contains an authenticated command injection vulnerability in the web confi... |
| CVE-2024-58305 | HIGH | 8.8 | 0.4% | Dec 12, 2025 | WonderCMS 4.3.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious JavaScript throu... |
| CVE-2024-58313 | HIGH | 7.2 | 0.5% | Dec 11, 2025 | xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative pr... |
| CVE-2024-58312 | HIGH | 7.5 | 1.0% | Dec 11, 2025 | xbtitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system ... |
| CVE-2024-58310 | HIGH | 8.7 | 0.8% | Dec 11, 2025 | APC Network Management Card 4 contains a path traversal vulnerability that allows unauthenticated attackers to access se... |
| CVE-2024-58307 | HIGH | 8.8 | 0.4% | Dec 11, 2025 | CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authent... |
| CVE-2024-58306 | HIGH | 8.7 | 0.4% | Dec 11, 2025 | minaliC 2.0.0 contains a denial of service vulnerability that allows remote attackers to crash the web server by sending... |
| CVE-2024-58303 | HIGH | 8.6 | 0.5% | Dec 11, 2025 | FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject... |
| CVE-2024-58300 | HIGH | 8.7 | 0.4% | Dec 11, 2025 | Siklu MultiHaul TG series devices before version 2.0.0 contain an unauthenticated vulnerability that allows remote attac... |
| CVE-2024-58295 | HIGH | 8.6 | 0.6% | Dec 11, 2025 | ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload ma... |
| CVE-2024-58294 | HIGH | 8.8 | 3.1% | Dec 11, 2025 | FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with va... |
| CVE-2024-58293 | HIGH | 8.6 | 0.3% | Dec 11, 2025 | Akaunting 3.1.8 contains a server-side template injection vulnerability that allows authenticated administrators to exec... |
| CVE-2024-58288 | HIGH | 8.7 | 0.4% | Dec 11, 2025 | Genexus Protection Server 9.7.2.10 contains an unquoted service path vulnerability in the protsrvservice Windows service... |
| CVE-2024-58287 | HIGH | 8.8 | 3.0% | Dec 11, 2025 | reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that all... |
| CVE-2024-8273 | HIGH | 8.8 | 0.3% | Dec 11, 2025 | Authentication Bypass by Spoofing vulnerability in HYPR Server allows Identity Spoofing.This issue affects Server: befor... |
| CVE-2024-58284 | HIGH | 7.2 | 1.1% | Dec 10, 2025 | PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inj... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now