2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43181 | MEDIUM | 6.3 | 0.2% | Feb 4, 2026 | IBM Concert 1.0.0 through 2.1.0 does not invalidate session after logout which could allow an authenticated user to impe... |
| CVE-2024-40685 | MEDIUM | 4.3 | 0.1% | Feb 4, 2026 | IBM Operations Analytics – Log Analysis versions 1.3.5.0 through 1.3.8.3 and IBM SmartCloud Analytics – Log Analysis are... |
| CVE-2024-39724 | MEDIUM | 5.3 | 0.3% | Feb 4, 2026 | IBM Db2 Big SQL on Cloud Pak for Data versions 7.6 (on CP4D 4.8), 7.7 (on CP4D 5.0), and 7.8 (on CP4D 5.1) do not proper... |
| CVE-2024-4147 | MEDIUM | 6.5 | 0.4% | Feb 2, 2026 | In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to delete p... |
| CVE-2024-9432 | MEDIUM | 6.9 | 0.1% | Jan 30, 2026 | Cleartext Storage of Sensitive Information vulnerability in OpenText™ Vertica allows Retrieve Embedded Sensitive Data. ... |
| CVE-2024-54855 | MEDIUM | 6.4 | 0.3% | Jan 13, 2026 | fabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain static keys for the SSH service, allowing attac... |
| CVE-2024-14020 | MEDIUM | 5 | 0.3% | Jan 7, 2026 | A weakness has been identified in carboneio carbone up to fbcd349077ad0e8748be73eab2a82ea92b6f8a7e. This impacts an unkn... |
| CVE-2024-31088 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPShop.Ru A... |
| CVE-2024-23511 | MEDIUM | 6.5 | 0.1% | Jan 5, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in POSIMYTH Th... |
| CVE-2024-55374 | MEDIUM | 5.3 | 0.3% | Jan 2, 2026 | REDCap 14.3.13 allows an attacker to enumerate usernames due to an observable discrepancy between login attempts. |
| CVE-2024-42718 | MEDIUM | 6.5 | 0.6% | Dec 26, 2025 | A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially craft... |
| CVE-2024-29720 | MEDIUM | 5.5 | 0.2% | Dec 26, 2025 | An issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 allows a local attacker to obtain sensitive information via... |
| CVE-2024-40317 | MEDIUM | 6.1 | 0.2% | Dec 24, 2025 | A reflected cross-site scripting (XSS) vulnerability in MyNET up to v26.08 allows attackers to execute arbitrary code in... |
| CVE-2024-39037 | MEDIUM | 6.5 | 0.2% | Dec 24, 2025 | MyNET up to v26.08.316 was discovered to contain an Unauthenticated SQL Injection vulnerability via the intmenu paramete... |
| CVE-2024-35322 | MEDIUM | 6.1 | 0.2% | Dec 24, 2025 | MyNET up to v26.08 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the ficheiro param... |
| CVE-2024-58335 | MEDIUM | 5 | 0.2% | Dec 24, 2025 | OpenXRechnungToolbox through 2024-10-05-3.0.0 before 6c50e89 allows XXE because the disallow-doctype-decl feature is not... |
| CVE-2024-25812 | MEDIUM | 6.1 | 0.2% | Dec 22, 2025 | MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the src parameter. |
| CVE-2024-35321 | MEDIUM | 4.3 | 0.3% | Dec 22, 2025 | MyNET up to v26.08 was discovered to contain a Reflected cross-site scripting (XSS) vulnerability via the msgtipo parame... |
| CVE-2024-25814 | MEDIUM | 6.1 | 0.2% | Dec 22, 2025 | MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the msg parameter. |
| CVE-2024-58323 | MEDIUM | 5.4 | 0.1% | Dec 18, 2025 | A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Ch... |
| CVE-2024-58322 | MEDIUM | 5.4 | 0.1% | Dec 18, 2025 | A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious code into shipping... |
| CVE-2024-58321 | MEDIUM | 5.4 | 0.1% | Dec 18, 2025 | A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form v... |
| CVE-2024-58320 | MEDIUM | 6.9 | 0.2% | Dec 18, 2025 | An information disclosure vulnerability in Kentico Xperience allows public users to access sensitive administration inte... |
| CVE-2024-58319 | MEDIUM | 6.1 | 0.2% | Dec 18, 2025 | A reflected cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the... |
| CVE-2024-58318 | MEDIUM | 6.1 | 0.1% | Dec 18, 2025 | A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the ri... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now