2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39024 | HIGH | 8.8 | 0.4% | Aug 6, 2026 | In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution. |
| CVE-2024-6832 | HIGH | 7.5 | 0.3% | Aug 6, 2026 | The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not mainta... |
| CVE-2024-25039 | HIGH | 7.5 | 0.3% | Jul 30, 2026 | IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1... |
| CVE-2024-14041 | HIGH | 8.2 | 0.3% | Jul 28, 2026 | In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polyno... |
| CVE-2024-14040 | HIGH | 7.8 | 0.1% | Jul 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Increase weight to u16 In CLOS netwo... |
| CVE-2024-58330 | HIGH | 7.5 | 0.5% | Jul 23, 2026 | A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to ret... |
| CVE-2024-58023 | HIGH | 8.4 | 0.1% | Jul 23, 2026 | Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive inform... |
| CVE-2024-51316 | HIGH | 7.5 | 0.2% | Jul 20, 2026 | The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /g... |
| CVE-2024-58369 | HIGH | 7.1 | 0.2% | Jul 18, 2026 | SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or names... |
| CVE-2024-58368 | HIGH | 8.7 | 0.4% | Jul 18, 2026 | SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing s... |
| CVE-2024-58367 | HIGH | 7.1 | 0.2% | Jul 18, 2026 | SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations,... |
| CVE-2024-58365 | HIGH | 7.1 | 0.2% | Jul 18, 2026 | SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls ... |
| CVE-2024-58362 | HIGH | 8.8 | 0.4% | Jul 18, 2026 | SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operati... |
| CVE-2024-58361 | HIGH | 7.1 | 0.2% | Jul 18, 2026 | SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code ... |
| CVE-2024-58359 | HIGH | 7.1 | 0.3% | Jul 18, 2026 | SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY r... |
| CVE-2024-58357 | HIGH | 7.1 | 0.3% | Jul 18, 2026 | SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics whe... |
| CVE-2024-34268 | HIGH | 7.1 | 0.2% | Jul 16, 2026 | EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow ... |
| CVE-2024-32386 | HIGH | 7.3 | 0.4% | Jul 16, 2026 | Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote at... |
| CVE-2024-7708 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is parti... |
| CVE-2024-6228 | HIGH | 7.5 | 0.3% | Jul 6, 2026 | The Notifications for Forms & WordPress Actions WordPress plugin before 2.6 does not validate a user-supplied value befo... |
| CVE-2024-58352 | HIGH | 8.7 | — | Jul 2, 2026 | Landray OA contains an unauthenticated HQL injection vulnerability that allows unauthenticated attackers to query arbitr... |
| CVE-2024-23581 | HIGH | 7.8 | 0.1% | Jun 26, 2026 | The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized ... |
| CVE-2024-49269 | HIGH | 7.1 | 0.2% | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions. |
| CVE-2024-32949 | HIGH | 8.3 | 0.3% | Jun 17, 2026 | Missing Authorization vulnerability in Prince Integrate Google Drive allows Exploiting Incorrectly Configured Access Con... |
| CVE-2024-32729 | HIGH | 7.5 | 0.4% | Jun 17, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversatio... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now