2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36311 | MEDIUM | 4.6 | 0.1% | Feb 10, 2026 | A Time-of-check time-of-use (TOCTOU) race condition in the SMM communications buffer could allow a privileged attacker t... |
| CVE-2024-36310 | MEDIUM | 4.6 | 0.2% | Feb 10, 2026 | Improper input validation in the SMM communications buffer could allow a privileged attacker to perform an out of bounds... |
| CVE-2024-21953 | MEDIUM | 5.9 | 0.2% | Feb 10, 2026 | Improper input validation in IOMMU could allow a malicious hypervisor to reconfigure IOMMU registers resulting in loss o... |
| CVE-2024-54192 | MEDIUM | 5.5 | 0.1% | Feb 10, 2026 | An issue inTcpreplay v4.5.1 allows a local attacker to cause a denial of service via a crafted file to the tcpedit_dlt_g... |
| CVE-2024-52334 | MEDIUM | 6.3 | 0.3% | Feb 10, 2026 | A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The affected application does not ... |
| CVE-2024-51451 | MEDIUM | 6.5 | 0.2% | Feb 4, 2026 | IBM Concert 1.0.0 through 2.1.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HO... |
| CVE-2024-43181 | MEDIUM | 6.3 | 0.2% | Feb 4, 2026 | IBM Concert 1.0.0 through 2.1.0 does not invalidate session after logout which could allow an authenticated user to impe... |
| CVE-2024-40685 | MEDIUM | 4.3 | 0.1% | Feb 4, 2026 | IBM Operations Analytics – Log Analysis versions 1.3.5.0 through 1.3.8.3 and IBM SmartCloud Analytics – Log Analysis are... |
| CVE-2024-39724 | MEDIUM | 5.3 | 0.3% | Feb 4, 2026 | IBM Db2 Big SQL on Cloud Pak for Data versions 7.6 (on CP4D 4.8), 7.7 (on CP4D 5.0), and 7.8 (on CP4D 5.1) do not proper... |
| CVE-2024-5986 | CRITICAL | 9.1 | 0.6% | Feb 2, 2026 | A vulnerability in h2oai/h2o-3 version 3.46.0.1 allows remote attackers to write arbitrary data to any file on the serve... |
| CVE-2024-5386 | HIGH | 8.8 | 0.5% | Feb 2, 2026 | In lunary-ai/lunary version 1.2.2, an account hijacking vulnerability exists due to a password reset token leak. A user ... |
| CVE-2024-4147 | MEDIUM | 6.5 | 0.4% | Feb 2, 2026 | In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to delete p... |
| CVE-2024-2356 | CRITICAL | 9.6 | 0.8% | Feb 2, 2026 | A Local File Inclusion (LFI) vulnerability exists in the '/reinstall_extension' endpoint of the parisneo/lollms-webui ap... |
| CVE-2024-54263 | HIGH | 7.5 | 0.3% | Feb 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-9432 | MEDIUM | 6.9 | 0.1% | Jan 30, 2026 | Cleartext Storage of Sensitive Information vulnerability in OpenText™ Vertica allows Retrieve Embedded Sensitive Data. ... |
| CVE-2024-4027 | HIGH | 7.5 | 0.6% | Jan 30, 2026 | A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an... |
| CVE-2024-11976 | HIGH | 7.3 | 0.4% | Jan 23, 2026 | The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includ... |
| CVE-2024-53252 | — | — | — | Jan 22, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used. |
| CVE-2024-53251 | — | — | — | Jan 22, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used. |
| CVE-2024-53250 | — | — | — | Jan 22, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used. |
| CVE-2024-53249 | — | — | — | Jan 22, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used. |
| CVE-2024-53248 | — | — | — | Jan 22, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used. |
| CVE-2024-45743 | — | — | — | Jan 22, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used. |
| CVE-2024-45742 | — | — | — | Jan 22, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used. |
| CVE-2024-45730 | — | — | — | Jan 22, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now