2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11920 | MEDIUM | 4.3 | 0.2% | Nov 14, 2025 | Inappropriate implementation in Dawn in Google Chrome on Mac prior to 130.0.6723.92 allowed a remote attacker to perform... |
| CVE-2024-11919 | MEDIUM | 4.3 | 0.2% | Nov 14, 2025 | Inappropriate implementation in Intents in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker to ... |
| CVE-2024-48829 | MEDIUM | 6.7 | 0.2% | Nov 12, 2025 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Control of Generation of Code ('Code Inj... |
| CVE-2024-45301 | MEDIUM | 5.3 | 0.2% | Nov 12, 2025 | Mintty is a terminal emulator for Cygwin, MSYS, and WSL. In versions 2.3.6 through 3.7.4, several escape sequences can c... |
| CVE-2024-32014 | MEDIUM | 5.6 | 0.1% | Nov 11, 2025 | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application i... |
| CVE-2024-13998 | MEDIUM | 6.5 | 0.9% | Nov 3, 2025 | Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (includ... |
| CVE-2024-51317 | MEDIUM | 6.5 | 0.4% | Nov 3, 2025 | An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function |
| CVE-2024-13992 | MEDIUM | 5.4 | 0.5% | Oct 31, 2025 | Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing pag... |
| CVE-2024-14006 | MEDIUM | 6.1 | 0.4% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-su... |
| CVE-2024-14002 | MEDIUM | 5.5 | 1.2% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.4 contain a local file inclusion (LFI) vulnerability via its NagVis integration. An... |
| CVE-2024-14001 | MEDIUM | 5.4 | 0.5% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Executive Summary Report com... |
| CVE-2024-14000 | MEDIUM | 5.4 | 0.5% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Capacity Planning Report com... |
| CVE-2024-13993 | MEDIUM | 6.1 | 0.7% | Oct 30, 2025 | Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) via the login page whe... |
| CVE-2024-58269 | MEDIUM | 4.3 | 0.3% | Oct 29, 2025 | A vulnerability has been identified in Rancher Manager, where sensitive information, including secret data, cluster imp... |
| CVE-2024-45161 | MEDIUM | 4.6 | 0.1% | Oct 29, 2025 | A CSRF issue was discovered in the administrative web GUI in Blu-Castle BCUM221E 1.0.0P220507. This can be exploited via... |
| CVE-2024-31573 | MEDIUM | 4 | 0.2% | Oct 17, 2025 | XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (us... |
| CVE-2024-42192 | MEDIUM | 5.5 | 0.1% | Oct 16, 2025 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access... |
| CVE-2024-47569 | MEDIUM | 4.3 | 0.4% | Oct 14, 2025 | A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7... |
| CVE-2024-26008 | MEDIUM | 5.3 | 0.4% | Oct 14, 2025 | An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 a... |
| CVE-2024-44088 | MEDIUM | 6.1 | 0.6% | Oct 14, 2025 | Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability all... |
| CVE-2024-57494 | MEDIUM | 6.5 | 0.3% | Oct 1, 2025 | Cross Site Scripting vulnerability in Neto E-Commerce CMS v.6.313.0 through v.6.3115 allows a remote attacker to escalat... |
| CVE-2024-5200 | MEDIUM | 4.8 | 0.2% | Sep 29, 2025 | The Postie WordPress plugin before 1.9.71 does not sanitise and escape some of its settings, which could allow high priv... |
| CVE-2024-58241 | MEDIUM | 5.5 | 0.1% | Sep 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Disable works on hci_unregiste... |
| CVE-2024-21935 | MEDIUM | 5 | 0.2% | Sep 23, 2025 | Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to manipulate R... |
| CVE-2024-21927 | MEDIUM | 5 | 0.3% | Sep 23, 2025 | Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to use certain ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now