2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-58304 | HIGH | 7.5 | 0.4% | Dec 11, 2025 | SPA-CART CMS 1.9.0.3 contains a stored cross-site scripting vulnerability in the product description parameter that allo... |
| CVE-2024-58303 | HIGH | 8.6 | 0.5% | Dec 11, 2025 | FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject... |
| CVE-2024-58300 | HIGH | 8.7 | 0.3% | Dec 11, 2025 | Siklu MultiHaul TG series devices before version 2.0.0 contain an unauthenticated vulnerability that allows remote attac... |
| CVE-2024-58295 | HIGH | 8.6 | 0.5% | Dec 11, 2025 | ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload ma... |
| CVE-2024-58294 | HIGH | 8.8 | 3.1% | Dec 11, 2025 | FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with va... |
| CVE-2024-58293 | HIGH | 8.6 | 0.3% | Dec 11, 2025 | Akaunting 3.1.8 contains a server-side template injection vulnerability that allows authenticated administrators to exec... |
| CVE-2024-58288 | HIGH | 8.7 | 0.3% | Dec 11, 2025 | Genexus Protection Server 9.7.2.10 contains an unquoted service path vulnerability in the protsrvservice Windows service... |
| CVE-2024-58287 | HIGH | 8.8 | 3.0% | Dec 11, 2025 | reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that all... |
| CVE-2024-8273 | HIGH | 8.8 | 0.3% | Dec 11, 2025 | Authentication Bypass by Spoofing vulnerability in HYPR Server allows Identity Spoofing.This issue affects Server: befor... |
| CVE-2024-58284 | HIGH | 7.2 | 0.9% | Dec 10, 2025 | PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inj... |
| CVE-2024-58283 | HIGH | 8.8 | 0.6% | Dec 10, 2025 | WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload mali... |
| CVE-2024-58282 | HIGH | 7.2 | 0.9% | Dec 10, 2025 | Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload mali... |
| CVE-2024-58281 | HIGH | 8.8 | 0.8% | Dec 10, 2025 | Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP... |
| CVE-2024-58280 | HIGH | 8.8 | 0.8% | Dec 10, 2025 | CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file exten... |
| CVE-2024-58279 | HIGH | 8.8 | 0.8% | Dec 10, 2025 | appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to uplo... |
| CVE-2024-2104 | HIGH | 8.8 | 0.2% | Dec 10, 2025 | Due to improper BLE security configurations on the device's GATT server, an adjacent unauthenticated attacker can read a... |
| CVE-2024-56840 | HIGH | 7.5 | 0.6% | Dec 9, 2025 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio... |
| CVE-2024-56839 | HIGH | 8.6 | 0.6% | Dec 9, 2025 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio... |
| CVE-2024-56838 | HIGH | 8.6 | 0.4% | Dec 9, 2025 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio... |
| CVE-2024-56837 | HIGH | 8.6 | 0.5% | Dec 9, 2025 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio... |
| CVE-2024-56836 | HIGH | 8.8 | 0.4% | Dec 9, 2025 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio... |
| CVE-2024-56835 | HIGH | 8.8 | 0.5% | Dec 9, 2025 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio... |
| CVE-2024-58278 | HIGH | 8.5 | 0.2% | Dec 4, 2025 | perl2exe <= V30.10C contains an arbitrary code execution vulnerability that allows local authenticated attackers to exec... |
| CVE-2024-58277 | HIGH | 8.7 | 0.3% | Dec 4, 2025 | R Radio Network FM Transmitter 1.07 allows unauthenticated attackers to access the admin user's password through the sys... |
| CVE-2024-58276 | HIGH | 8.7 | 0.4% | Dec 4, 2025 | Obi08/Enrollment System 1.0 contains a SQL injection vulnerability in the keyword parameter of /get_subject.php that all... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now