2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31027 | MEDIUM | 5.4 | — | Sep 29, 2026 | Cross Site Scripting vulnerability in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote att... |
| CVE-2024-58386 | MEDIUM | 6.5 | 0.4% | Sep 28, 2026 | ZoneMinder versions 1.37.0 before 1.38.0 contain a path traversal vulnerability in the files view that allows authentica... |
| CVE-2024-56344 | MEDIUM | 5.9 | 0.2% | Sep 18, 2026 | IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain se... |
| CVE-2024-38639 | MEDIUM | 4.8 | 0.2% | Sep 18, 2026 | An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the ... |
| CVE-2024-27123 | MEDIUM | 5.2 | 0.1% | Sep 18, 2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent. The local attackers can then exploit t... |
| CVE-2024-11222 | MEDIUM | 6.4 | 0.2% | Sep 16, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 1... |
| CVE-2024-58384 | MEDIUM | 5.4 | 0.2% | Sep 15, 2026 | Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return... |
| CVE-2024-23176 | MEDIUM | 5.4 | 0.2% | Sep 14, 2026 | An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss... |
| CVE-2024-53922 | MEDIUM | 5.7 | 0.2% | Sep 14, 2026 | An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. L... |
| CVE-2024-12145 | MEDIUM | 4.3 | — | Sep 11, 2026 | The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi... |
| CVE-2024-58380 | MEDIUM | 6.5 | 0.4% | Sep 9, 2026 | PocketMine-MP versions before 5.11.2 contain a denial of service vulnerability in BookEditPacket handling that crashes t... |
| CVE-2024-3773 | MEDIUM | 5.9 | 0.1% | Sep 2, 2026 | The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes b... |
| CVE-2024-58379 | MEDIUM | 5.3 | 0.3% | Aug 31, 2026 | nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUr... |
| CVE-2024-58376 | MEDIUM | 6.7 | 0.7% | Aug 19, 2026 | Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAli... |
| CVE-2024-14046 | MEDIUM | 6.3 | 0.4% | Aug 18, 2026 | A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController ... |
| CVE-2024-14045 | MEDIUM | 6.3 | 0.4% | Aug 18, 2026 | A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/... |
| CVE-2024-14044 | MEDIUM | 6.3 | 0.5% | Aug 12, 2026 | A vulnerability was identified in Open5GS up to 2.7.1. This issue affects the function pcrf_rx_aar_cb of the file src/pc... |
| CVE-2024-14043 | MEDIUM | 6.3 | 0.5% | Aug 12, 2026 | A vulnerability was determined in Open5GS up to 2.7.1. This vulnerability affects the function mme_s6a_subscription_data... |
| CVE-2024-14042 | MEDIUM | 6.3 | 0.5% | Aug 11, 2026 | A vulnerability was found in Open5GS up to 2.7.1. This affects the function hss_ogs_diam_s6a_air_cb/hss_ogs_diam_s6a_ulr... |
| CVE-2024-6541 | MEDIUM | 6.8 | 0.3% | Aug 6, 2026 | The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dy... |
| CVE-2024-8995 | MEDIUM | 4.9 | 0.1% | Aug 6, 2026 | Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This a... |
| CVE-2024-10302 | MEDIUM | 5.8 | 0.2% | Aug 6, 2026 | The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allo... |
| CVE-2024-40683 | MEDIUM | 6.3 | 0.3% | Jul 30, 2026 | IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2,... |
| CVE-2024-14041 | MEDIUM | 5.9 | 0.3% | Jul 28, 2026 | In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polyno... |
| CVE-2024-5300 | MEDIUM | 5.6 | — | Jul 21, 2026 | An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configura... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now