2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52890 | MEDIUM | 6.1 | 0.2% | Aug 5, 2025 | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.03 could be susceptible to cross-site scripting due to n... |
| CVE-2024-45183 | MEDIUM | 6.5 | 0.2% | Aug 4, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, and 2400. A lack of a JPE... |
| CVE-2024-51775 | MEDIUM | 5.3 | 0.2% | Aug 3, 2025 | Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server... |
| CVE-2024-52279 | MEDIUM | 5.3 | 0.9% | Aug 3, 2025 | Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not ac... |
| CVE-2024-41177 | MEDIUM | 6.1 | 0.6% | Aug 3, 2025 | Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: befo... |
| CVE-2024-34327 | MEDIUM | 6.5 | 0.3% | Jul 31, 2025 | Sielox AnyWare v2.1.2 was discovered to contain a SQL injection vulnerability via the email address field of the passwor... |
| CVE-2024-34328 | MEDIUM | 6.3 | 0.2% | Jul 31, 2025 | An open redirect in Sielox AnyWare v2.1.2 allows attackers to execute a man-in-the-middle attack via a crafted URL. |
| CVE-2024-45515 | MEDIUM | 6.1 | 0.3% | Jul 30, 2025 | An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability exists in... |
| CVE-2024-43018 | MEDIUM | 6.4 | 0.3% | Jul 29, 2025 | Piwigo 13.8.0 and below is vulnerable to SQL Injection in the parameters max_level and min_register. These parameters ar... |
| CVE-2024-52894 | MEDIUM | 4.9 | 0.3% | Jul 29, 2025 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 1... |
| CVE-2024-49343 | MEDIUM | 5.4 | 0.2% | Jul 28, 2025 | IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HT... |
| CVE-2024-58265 | MEDIUM | 4.3 | 0.4% | Jul 27, 2025 | The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby deny... |
| CVE-2024-58263 | MEDIUM | 5.3 | 0.4% | Jul 27, 2025 | The cosmwasm-std crate before 2.0.2 for Rust allows integer overflows that cause incorrect contract calculations. |
| CVE-2024-58262 | MEDIUM | 5.1 | 0.2% | Jul 27, 2025 | The curve25519-dalek crate before 4.1.3 for Rust has a constant-time operation on elliptic curve scalars that is removed... |
| CVE-2024-48730 | MEDIUM | 6.5 | 0.5% | Jul 25, 2025 | The default configuration in ETSI Open-Source MANO (OSM) v.14.x, v.15.x, v.16.x, v.17.x does not impose any restrictions... |
| CVE-2024-41751 | MEDIUM | 5.5 | 0.1% | Jul 23, 2025 | IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, au... |
| CVE-2024-41750 | MEDIUM | 5.5 | 0.1% | Jul 23, 2025 | IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, au... |
| CVE-2024-40686 | MEDIUM | 6.1 | 0.2% | Jul 23, 2025 | IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 is vulnerable to HTTP h... |
| CVE-2024-40682 | MEDIUM | 5.5 | 0.1% | Jul 23, 2025 | IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local use... |
| CVE-2024-53288 | MEDIUM | 5.9 | 0.2% | Jul 23, 2025 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in NTP Region functio... |
| CVE-2024-53287 | MEDIUM | 5.9 | 0.2% | Jul 23, 2025 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functi... |
| CVE-2024-38335 | MEDIUM | 4.5 | 0.2% | Jul 22, 2025 | IBM Security QRadar Network Threat Analytics 1.0.0 through 1.3.1 could allow a privileged user to cause a denial of serv... |
| CVE-2024-55040 | MEDIUM | 6.1 | 0.7% | Jul 21, 2025 | Cross Site Scripting vulnerability in Sensaphone WEB600 Monitoring System v.1.6.5.H and before allows a remote attacker ... |
| CVE-2024-13175 | MEDIUM | 5.5 | 0.1% | Jul 18, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Vidco Software VOC TESTER allows Forceful Browsing. T... |
| CVE-2024-32124 | MEDIUM | 4.3 | 0.3% | Jul 18, 2025 | An improper access control vulnerability [CWE-284] in FortiIsolator version 2.4.4, version 2.4.3, 2.3 all versions loggi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now