2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49828 | HIGH | 7.5 | 0.3% | Jul 29, 2025 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 1... |
| CVE-2024-42655 | HIGH | 8.8 | 0.3% | Jul 29, 2025 | An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system ... |
| CVE-2024-42651 | HIGH | 7.5 | 0.4% | Jul 29, 2025 | NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vuln... |
| CVE-2024-42645 | HIGH | 7.5 | 0.5% | Jul 29, 2025 | An issue in FlashMQ v1.14.0 allows attackers to cause an assertion failure via sending a crafted retain message, leading... |
| CVE-2024-42644 | HIGH | 7.5 | 0.5% | Jul 29, 2025 | FlashMQ v1.14.0 was discovered to contain an assertion failure in the function PublishCopyFactory::getNewPublish, which ... |
| CVE-2024-49343 | MEDIUM | 5.4 | 0.2% | Jul 28, 2025 | IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HT... |
| CVE-2024-49342 | HIGH | 7.5 | 0.3% | Jul 28, 2025 | IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacke... |
| CVE-2024-58266 | CRITICAL | 9.8 | 0.8% | Jul 27, 2025 | The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may fa... |
| CVE-2024-58265 | MEDIUM | 4.3 | 0.4% | Jul 27, 2025 | The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby deny... |
| CVE-2024-58264 | HIGH | 7.5 | 0.4% | Jul 27, 2025 | The serde-json-wasm crate before 1.0.1 for Rust allows stack consumption via deeply nested JSON data. |
| CVE-2024-58263 | MEDIUM | 5.3 | 0.4% | Jul 27, 2025 | The cosmwasm-std crate before 2.0.2 for Rust allows integer overflows that cause incorrect contract calculations. |
| CVE-2024-58262 | MEDIUM | 5.1 | 0.2% | Jul 27, 2025 | The curve25519-dalek crate before 4.1.3 for Rust has a constant-time operation on elliptic curve scalars that is removed... |
| CVE-2024-58261 | HIGH | 7.5 | 0.4% | Jul 27, 2025 | The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: N... |
| CVE-2024-13507 | HIGH | 7.5 | 0.4% | Jul 26, 2025 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to ... |
| CVE-2024-13976 | HIGH | 8.5 | 0.2% | Jul 25, 2025 | A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During th... |
| CVE-2024-13975 | HIGH | 8.5 | 0.1% | Jul 25, 2025 | A local privilege escalation vulnerability exists in Commvault for Windows versions 11.20.0, 11.28.0, 11.32.0, 11.34.0, ... |
| CVE-2024-48730 | MEDIUM | 6.5 | 0.5% | Jul 25, 2025 | The default configuration in ETSI Open-Source MANO (OSM) v.14.x, v.15.x, v.16.x, v.17.x does not impose any restrictions... |
| CVE-2024-48729 | HIGH | 7.1 | 0.3% | Jul 25, 2025 | An issue in ETSI Open-Source MANO (OSM) 14.0.x before 14.0.3, 15.0.x before 15.0.2, 16.0.0, and 17.0.0 allows a remote a... |
| CVE-2024-41751 | MEDIUM | 5.5 | 0.1% | Jul 23, 2025 | IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, au... |
| CVE-2024-41750 | MEDIUM | 5.5 | 0.1% | Jul 23, 2025 | IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, au... |
| CVE-2024-40686 | MEDIUM | 6.1 | 0.2% | Jul 23, 2025 | IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 is vulnerable to HTTP h... |
| CVE-2024-40682 | MEDIUM | 5.5 | 0.1% | Jul 23, 2025 | IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local use... |
| CVE-2024-12310 | HIGH | 7 | 0.2% | Jul 23, 2025 | A vulnerability in Imprivata Enterprise Access Management (formerly Imprivata OneSign) allows bypassing the login screen... |
| CVE-2024-53288 | MEDIUM | 5.9 | 0.2% | Jul 23, 2025 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in NTP Region functio... |
| CVE-2024-53287 | MEDIUM | 5.9 | 0.2% | Jul 23, 2025 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now