2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48077 | HIGH | 7.5 | 0.3% | Jan 15, 2026 | NanoMQ v0.22.7 is vulnerable to Denial of Service (DoS) due to improper resource throttling. A crafted sequence of reque... |
| CVE-2024-54855 | MEDIUM | 6.4 | 0.3% | Jan 13, 2026 | fabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain static keys for the SSH service, allowing attac... |
| CVE-2024-58340 | HIGH | 7.5 | 0.4% | Jan 12, 2026 | LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) vulnerability in the... |
| CVE-2024-58339 | HIGH | 7.5 | 0.6% | Jan 12, 2026 | LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vuln... |
| CVE-2024-14021 | HIGH | 7.8 | 0.3% | Jan 12, 2026 | LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability i... |
| CVE-2024-14020 | MEDIUM | 5 | 0.3% | Jan 7, 2026 | A weakness has been identified in carboneio carbone up to fbcd349077ad0e8748be73eab2a82ea92b6f8a7e. This impacts an unkn... |
| CVE-2024-31088 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPShop.Ru A... |
| CVE-2024-30547 | HIGH | 7.1 | 0.2% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Shazdeh Hea... |
| CVE-2024-56825 | — | — | — | Jan 5, 2026 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2024-56809 | — | — | — | Jan 5, 2026 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2024-53735 | HIGH | 7.1 | 0.1% | Jan 5, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in corourke iPhone We... |
| CVE-2024-30516 | HIGH | 7.5 | 0.2% | Jan 5, 2026 | Improper Validation of Specified Quantity in Input vulnerability in SaasProject Booking Package allows Accessing Functio... |
| CVE-2024-30461 | HIGH | 7.1 | 0.1% | Jan 5, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tumult Inc ... |
| CVE-2024-23511 | MEDIUM | 6.5 | 0.1% | Jan 5, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in POSIMYTH Th... |
| CVE-2024-55374 | MEDIUM | 5.3 | 0.3% | Jan 2, 2026 | REDCap 14.3.13 allows an attacker to enumerate usernames due to an observable discrepancy between login attempts. |
| CVE-2024-58338 | CRITICAL | 10 | 0.7% | Dec 30, 2025 | Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed ... |
| CVE-2024-58337 | HIGH | 8.7 | 0.2% | Dec 30, 2025 | Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to... |
| CVE-2024-58336 | HIGH | 8.7 | 0.3% | Dec 30, 2025 | Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video s... |
| CVE-2024-58315 | HIGH | 8.5 | 0.2% | Dec 30, 2025 | Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that allows local non-privileged users to pote... |
| CVE-2024-58247 | — | — | — | Dec 30, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w... |
| CVE-2024-58246 | — | — | — | Dec 30, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w... |
| CVE-2024-58245 | — | — | — | Dec 30, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w... |
| CVE-2024-58244 | — | — | — | Dec 30, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w... |
| CVE-2024-58243 | — | — | — | Dec 30, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w... |
| CVE-2024-58242 | — | — | — | Dec 30, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now