2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51775 | MEDIUM | 5.3 | 0.2% | Aug 3, 2025 | Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server... |
| CVE-2024-52279 | MEDIUM | 5.3 | 0.9% | Aug 3, 2025 | Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not ac... |
| CVE-2024-41177 | MEDIUM | 6.1 | 0.6% | Aug 3, 2025 | Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: befo... |
| CVE-2024-13978 | LOW | 2.5 | 0.2% | Aug 1, 2025 | A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as problematic. Affected by this vulnerability is... |
| CVE-2024-34327 | MEDIUM | 6.5 | 0.3% | Jul 31, 2025 | Sielox AnyWare v2.1.2 was discovered to contain a SQL injection vulnerability via the email address field of the passwor... |
| CVE-2024-34328 | MEDIUM | 6.3 | 0.2% | Jul 31, 2025 | An open redirect in Sielox AnyWare v2.1.2 allows attackers to execute a man-in-the-middle attack via a crafted URL. |
| CVE-2024-11478 | — | — | — | Jul 30, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-48916 | HIGH | 8.1 | 0.2% | Jul 30, 2025 | Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an ... |
| CVE-2024-45955 | HIGH | 7.3 | 0.4% | Jul 30, 2025 | Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter. |
| CVE-2024-45515 | MEDIUM | 6.1 | 0.3% | Jul 30, 2025 | An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability exists in... |
| CVE-2024-43018 | MEDIUM | 6.4 | 0.3% | Jul 29, 2025 | Piwigo 13.8.0 and below is vulnerable to SQL Injection in the parameters max_level and min_register. These parameters ar... |
| CVE-2024-52894 | MEDIUM | 4.9 | 0.3% | Jul 29, 2025 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 1... |
| CVE-2024-51473 | HIGH | 7.5 | 0.3% | Jul 29, 2025 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 1... |
| CVE-2024-49828 | HIGH | 7.5 | 0.3% | Jul 29, 2025 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 1... |
| CVE-2024-42655 | HIGH | 8.8 | 0.3% | Jul 29, 2025 | An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system ... |
| CVE-2024-42651 | HIGH | 7.5 | 0.4% | Jul 29, 2025 | NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vuln... |
| CVE-2024-42645 | HIGH | 7.5 | 0.5% | Jul 29, 2025 | An issue in FlashMQ v1.14.0 allows attackers to cause an assertion failure via sending a crafted retain message, leading... |
| CVE-2024-42644 | HIGH | 7.5 | 0.5% | Jul 29, 2025 | FlashMQ v1.14.0 was discovered to contain an assertion failure in the function PublishCopyFactory::getNewPublish, which ... |
| CVE-2024-49343 | MEDIUM | 5.4 | 0.2% | Jul 28, 2025 | IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HT... |
| CVE-2024-49342 | HIGH | 7.5 | 0.3% | Jul 28, 2025 | IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacke... |
| CVE-2024-58266 | CRITICAL | 9.8 | 0.8% | Jul 27, 2025 | The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may fa... |
| CVE-2024-58265 | MEDIUM | 4.3 | 0.4% | Jul 27, 2025 | The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby deny... |
| CVE-2024-58264 | HIGH | 7.5 | 0.4% | Jul 27, 2025 | The serde-json-wasm crate before 1.0.1 for Rust allows stack consumption via deeply nested JSON data. |
| CVE-2024-58263 | MEDIUM | 5.3 | 0.4% | Jul 27, 2025 | The cosmwasm-std crate before 2.0.2 for Rust allows integer overflows that cause incorrect contract calculations. |
| CVE-2024-58262 | MEDIUM | 5.1 | 0.2% | Jul 27, 2025 | The curve25519-dalek crate before 4.1.3 for Rust has a constant-time operation on elliptic curve scalars that is removed... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now