2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-58388 | HIGH | 7.5 | — | Oct 1, 2026 | Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability t... |
| CVE-2024-58387 | HIGH | 7.5 | 0.7% | Sep 30, 2026 | Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint th... |
| CVE-2024-42002 | HIGH | 8.4 | 0.2% | Sep 28, 2026 | A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool... |
| CVE-2024-14029 | HIGH | 7.5 | 0.4% | Sep 15, 2026 | Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body a... |
| CVE-2024-58383 | HIGH | 7.3 | 0.1% | Sep 14, 2026 | Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via ... |
| CVE-2024-58382 | HIGH | 7.5 | — | Sep 9, 2026 | league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allo... |
| CVE-2024-58381 | HIGH | 7.5 | 0.4% | Sep 9, 2026 | PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote... |
| CVE-2024-7956 | HIGH | 7.6 | 0.3% | Sep 2, 2026 | A vulnerability exists in the affected products that allows a threat actor to gain access to user’s projects. To exploit... |
| CVE-2024-35585 | HIGH | 8.6 | 0.3% | Sep 2, 2026 | Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication. |
| CVE-2024-7953 | HIGH | 8.7 | — | Sep 1, 2026 | A vulnerability exists in the affected products that allows a threat actor to create a project and become the administra... |
| CVE-2024-7952 | HIGH | 8.7 | — | Sep 1, 2026 | A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to ... |
| CVE-2024-14047 | HIGH | 7.1 | 0.1% | Sep 1, 2026 | A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by u... |
| CVE-2024-10085 | HIGH | 8.2 | — | Sep 1, 2026 | CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of... |
| CVE-2024-13942 | HIGH | 7.6 | 0.2% | Aug 19, 2026 | Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack in case of booting from external me... |
| CVE-2024-58375 | HIGH | 7.5 | 0.4% | Aug 16, 2026 | OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into... |
| CVE-2024-58374 | HIGH | 7.5 | 0.7% | Aug 13, 2026 | Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows r... |
| CVE-2024-39024 | HIGH | 8.8 | 0.7% | Aug 6, 2026 | In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution. |
| CVE-2024-6832 | HIGH | 7.5 | 0.3% | Aug 6, 2026 | The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not mainta... |
| CVE-2024-25039 | HIGH | 7.5 | 0.5% | Jul 30, 2026 | IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1... |
| CVE-2024-14040 | HIGH | 7.8 | 0.1% | Jul 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Increase weight to u16 In CLOS netwo... |
| CVE-2024-58330 | HIGH | 7.5 | 0.5% | Jul 23, 2026 | A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to ret... |
| CVE-2024-58023 | HIGH | 8.4 | 0.1% | Jul 23, 2026 | Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive inform... |
| CVE-2024-51316 | HIGH | 7.5 | 0.2% | Jul 20, 2026 | The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /g... |
| CVE-2024-58369 | HIGH | 7.1 | 0.2% | Jul 18, 2026 | SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or names... |
| CVE-2024-58368 | HIGH | 8.7 | 0.4% | Jul 18, 2026 | SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing s... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now