2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-48077HIGH7.5NanoMQ v0.22.7 is vulnerable to Denial of Service (DoS) due to improper resource throttling. A crafted sequence of reque...
CVE-2024-54855MEDIUM6.4fabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain static keys for the SSH service, allowing attac...
CVE-2024-58340HIGH7.5LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) vulnerability in the...
CVE-2024-58339HIGH7.5LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vuln...
CVE-2024-14021HIGH7.8LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability i...
CVE-2024-14020MEDIUM5A weakness has been identified in carboneio carbone up to fbcd349077ad0e8748be73eab2a82ea92b6f8a7e. This impacts an unkn...
CVE-2024-31088MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPShop.Ru A...
CVE-2024-30547HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Shazdeh Hea...
CVE-2024-56825Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2024-56809Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2024-53735HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in corourke iPhone We...
CVE-2024-30516HIGH7.5Improper Validation of Specified Quantity in Input vulnerability in SaasProject Booking Package allows Accessing Functio...
CVE-2024-30461HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tumult Inc ...
CVE-2024-23511MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in POSIMYTH Th...
CVE-2024-55374MEDIUM5.3REDCap 14.3.13 allows an attacker to enumerate usernames due to an observable discrepancy between login attempts.
CVE-2024-58338CRITICAL10Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed ...
CVE-2024-58337HIGH8.7Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to...
CVE-2024-58336HIGH8.7Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video s...
CVE-2024-58315HIGH8.5Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that allows local non-privileged users to pote...
CVE-2024-58247Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w...
CVE-2024-58246Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w...
CVE-2024-58245Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w...
CVE-2024-58244Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w...
CVE-2024-58243Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w...
CVE-2024-58242Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now