2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-58317 | MEDIUM | 6.9 | 0.2% | Dec 18, 2025 | A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL requirements when sett... |
| CVE-2024-29370 | MEDIUM | 5.3 | 0.2% | Dec 17, 2025 | In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) c... |
| CVE-2024-58302 | MEDIUM | 6.9 | 0.3% | Dec 11, 2025 | FoF Pretty Mail 1.1.2 contains a local file inclusion vulnerability that allows administrative users to include arbitrar... |
| CVE-2024-58297 | MEDIUM | 5.4 | 0.2% | Dec 11, 2025 | PyroCMS v3.0.1 contains a stored cross-site scripting vulnerability in the admin redirects configuration that allows att... |
| CVE-2024-58296 | MEDIUM | 5.3 | 0.3% | Dec 11, 2025 | CE Phoenix v3.0.1 contains a stored cross-site scripting vulnerability in the currencies administration panel that allow... |
| CVE-2024-58292 | MEDIUM | 5.3 | 0.4% | Dec 11, 2025 | XMB Forum 1.9.12.06 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to... |
| CVE-2024-58291 | MEDIUM | 5.3 | 0.3% | Dec 11, 2025 | Flatboard 3.2 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject ma... |
| CVE-2024-58289 | MEDIUM | 5.4 | 0.2% | Dec 11, 2025 | Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject mal... |
| CVE-2024-42197 | MEDIUM | 5.5 | 0.1% | Dec 11, 2025 | HCL Workload Scheduler stores user credentials in plain text which can be read by a local user. |
| CVE-2024-40593 | MEDIUM | 4.4 | 0.1% | Dec 11, 2025 | A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, ... |
| CVE-2024-58285 | MEDIUM | 5.4 | 0.2% | Dec 10, 2025 | Chyrp 2.5.2 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scr... |
| CVE-2024-2105 | MEDIUM | 6.5 | 0.2% | Dec 10, 2025 | An unauthorised attacker within bluetooth range may use an improper validation during the BLE connection request to dead... |
| CVE-2024-47570 | MEDIUM | 6.6 | 0.3% | Dec 9, 2025 | An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 throug... |
| CVE-2024-38798 | MEDIUM | 5.8 | 0.1% | Dec 9, 2025 | EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized ... |
| CVE-2024-9183 | MEDIUM | 6.4 | 0.2% | Dec 5, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, a... |
| CVE-2024-49572 | MEDIUM | 6.5 | 0.2% | Dec 1, 2025 | A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A special... |
| CVE-2024-32388 | MEDIUM | 5.3 | 1.4% | Dec 1, 2025 | Due to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP... |
| CVE-2024-5540 | MEDIUM | 6.9 | 0.3% | Nov 27, 2025 | The reflective cross-site scripting vulnerability found in ALC WebCTRL and Carrier i-Vu in versions older than 8.0 affec... |
| CVE-2024-8528 | MEDIUM | 5.4 | 0.1% | Nov 19, 2025 | Reflected XSS using a specific URL in Automated Logic WebCTRL and Carrier i-VU can allow delivery of malicious payload d... |
| CVE-2024-44664 | MEDIUM | 6.5 | 0.2% | Nov 17, 2025 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and ... |
| CVE-2024-44661 | MEDIUM | 5.4 | 0.2% | Nov 17, 2025 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.... |
| CVE-2024-46335 | MEDIUM | 4.6 | 0.2% | Nov 17, 2025 | PHPGurukul Complaint Management System 2.0 is vulnerble to Cross Site Scripting (XSS) via the fromdate and todate parame... |
| CVE-2024-44663 | MEDIUM | 6.5 | 0.2% | Nov 17, 2025 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php. |
| CVE-2024-44662 | MEDIUM | 6.5 | 0.2% | Nov 17, 2025 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page. |
| CVE-2024-44660 | MEDIUM | 6.5 | 0.2% | Nov 17, 2025 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now