2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57232 | CRITICAL | 9.8 | 1.2% | May 5, 2025 | NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname p... |
| CVE-2024-57231 | CRITICAL | 9.8 | 1.2% | May 5, 2025 | NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname p... |
| CVE-2024-57230 | CRITICAL | 9.8 | 1.2% | May 5, 2025 | NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname p... |
| CVE-2024-57229 | CRITICAL | 9.8 | 1.2% | May 5, 2025 | NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the devname ... |
| CVE-2024-48905 | CRITICAL | 9.1 | 0.4% | May 1, 2025 | Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint. |
| CVE-2024-32499 | CRITICAL | 9.8 | 0.4% | Apr 28, 2025 | Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed. |
| CVE-2024-53636 | CRITICAL | 9.8 | 1.2% | Apr 26, 2025 | An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.... |
| CVE-2024-30152 | CRITICAL | 9.8 | 0.2% | Apr 25, 2025 | HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain acce... |
| CVE-2024-56156 | CRITICAL | 9 | 0.6% | Apr 25, 2025 | Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypa... |
| CVE-2024-40446 | CRITICAL | 9.8 | 0.6% | Apr 22, 2025 | An issue in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted script |
| CVE-2024-58250 | CRITICAL | 9.3 | 0.2% | Apr 22, 2025 | The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges. |
| CVE-2024-53591 | CRITICAL | 9.8 | 0.5% | Apr 18, 2025 | An issue in the login page of Seclore v3.27.5.0 allows attackers to bypass authentication via a brute force attack. |
| CVE-2024-29643 | CRITICAL | 9.1 | 0.5% | Apr 18, 2025 | An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component. |
| CVE-2024-53924 | CRITICAL | 9.8 | 0.8% | Apr 17, 2025 | Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell,... |
| CVE-2024-56518 | CRITICAL | 9.8 | 0.8% | Apr 17, 2025 | Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelc... |
| CVE-2024-55372 | CRITICAL | 9.8 | 0.5% | Apr 16, 2025 | Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to ... |
| CVE-2024-55371 | CRITICAL | 9.8 | 0.5% | Apr 16, 2025 | Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to res... |
| CVE-2024-40073 | CRITICAL | 9.8 | 0.4% | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template p... |
| CVE-2024-40072 | CRITICAL | 9.8 | 0.4% | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id paramet... |
| CVE-2024-40071 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_ge... |
| CVE-2024-22036 | CRITICAL | 9.1 | 0.7% | Apr 16, 2025 | A vulnerability has been identified within Rancher where a cluster or node driver can be used to escape the chroot jail... |
| CVE-2024-58136 | CRITICAL | 9.8 | 87.7% | Apr 10, 2025 | Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regres... |
| CVE-2024-55210 | CRITICAL | 9.8 | 0.5% | Apr 9, 2025 | An issue in TOTVS Framework (Linha Protheus) 12.1.2310 allows attackers to bypass multi-factor authentication (MFA) via ... |
| CVE-2024-12556 | CRITICAL | 9.8 | 0.4% | Apr 8, 2025 | Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal. |
| CVE-2024-48887 | CRITICAL | 9.8 | 11.3% | Apr 8, 2025 | A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to c... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now