2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-58343 | MEDIUM | 4.3 | 0.2% | Apr 16, 2026 | Vision Helpdesk before 5.7.0 (patched in 5.6.10) allows attackers to read user profiles via modified serialized cookie d... |
| CVE-2024-8010 | HIGH | 7.5 | 0.3% | Apr 16, 2026 | The component accepts XML input through the publisher without disabling external entity resolution. This allows maliciou... |
| CVE-2024-4867 | MEDIUM | 5.4 | 0.2% | Apr 16, 2026 | The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or p... |
| CVE-2024-10242 | MEDIUM | 6.1 | 0.2% | Apr 16, 2026 | The authentication endpoint fails to adequately validate user-supplied input before reflecting it back in the response. ... |
| CVE-2024-2374 | CRITICAL | 9.1 | 0.4% | Apr 16, 2026 | The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the ... |
| CVE-2024-53412 | HIGH | 8.4 | 0.6% | Apr 15, 2026 | Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shel... |
| CVE-2024-33618 | HIGH | 7.5 | 0.5% | Apr 15, 2026 | Uncontrolled Resource Consumption in Bosch VMS Central Server in Bosch VMS 12.0.1 allows attackers to consume excessiv... |
| CVE-2024-23104 | MEDIUM | 4.3 | 0.3% | Apr 14, 2026 | An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 t... |
| CVE-2024-9168 | — | — | — | Apr 14, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2024-1490 | HIGH | 7.2 | 0.7% | Apr 9, 2026 | An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management... |
| CVE-2024-36058 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fail... |
| CVE-2024-36057 | CRITICAL | 9.8 | 1.8% | Apr 7, 2026 | Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code ex... |
| CVE-2024-14032 | HIGH | 7.8 | 0.2% | Apr 6, 2026 | Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that ... |
| CVE-2024-14033 | HIGH | 8.7 | 0.4% | Apr 2, 2026 | Hirschmann EagleSDV firmware prior to 05.4.02 contains a denial-of-service vulnerability in TLS session establishment. A... |
| CVE-2024-14034 | CRITICAL | 9.8 | 0.5% | Apr 2, 2026 | Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) managem... |
| CVE-2024-44303 | HIGH | 7.5 | 0.3% | Apr 2, 2026 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1. A malicious application may be ... |
| CVE-2024-44286 | HIGH | 7.5 | 0.3% | Apr 2, 2026 | This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with ... |
| CVE-2024-44250 | HIGH | 8.2 | 0.2% | Apr 2, 2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be... |
| CVE-2024-44219 | HIGH | 7.5 | 0.3% | Apr 2, 2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. A malicious a... |
| CVE-2024-40858 | HIGH | 7.1 | 0.2% | Apr 2, 2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be... |
| CVE-2024-40849 | HIGH | 7.5 | 0.2% | Apr 2, 2026 | A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.1. An app may be able... |
| CVE-2024-43028 | CRITICAL | 9.8 | 1.5% | Apr 1, 2026 | A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to exe... |
| CVE-2024-40489 | CRITICAL | 9.8 | 0.5% | Apr 1, 2026 | There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows a... |
| CVE-2024-53828 | MEDIUM | 5.3 | 0.4% | Apr 1, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a vulnerability where an attacker sending a large v... |
| CVE-2024-58342 | MEDIUM | 6.1 | 0.1% | Apr 1, 2026 | XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now